2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5802 | HIGH | 7.5 | 38.8% | Dec 29, 2020 | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a special... |
| CVE-2020-5801 | HIGH | 7.5 | 25.2% | Dec 29, 2020 | An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled ex... |
| CVE-2020-29475 | MEDIUM | 4.8 | 1.1% | Dec 29, 2020 | nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability ca... |
| CVE-2020-17533 | HIGH | 8.1 | 3.7% | Dec 29, 2020 | Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy en... |
| CVE-2020-25847 | HIGH | 8.8 | 2.5% | Dec 29, 2020 | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h... |
| CVE-2020-35769 | CRITICAL | 9.8 | 1.7% | Dec 29, 2020 | miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program. |
| CVE-2020-26287 | HIGH | 8.7 | 1.4% | Dec 29, 2020 | HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can ... |
| CVE-2020-26286 | HIGH | 7.5 | 1.4% | Dec 29, 2020 | HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticat... |
| CVE-2020-13476 | MEDIUM | 4.8 | 0.7% | Dec 28, 2020 | NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module. |
| CVE-2020-13474 | MEDIUM | 6.5 | 0.7% | Dec 28, 2020 | In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-p... |
| CVE-2020-13473 | MEDIUM | 5.5 | 0.3% | Dec 28, 2020 | NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration... |
| CVE-2020-27172 | CRITICAL | 9.8 | 1.3% | Dec 28, 2020 | An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file resto... |
| CVE-2020-35766 | HIGH | 7.8 | 0.5% | Dec 28, 2020 | The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack agai... |
| CVE-2020-35730 | MEDIUM | 6.1 | 32.4% | Dec 28, 2020 | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack... |
| CVE-2020-35616 | HIGH | 7.5 | 6.1% | Dec 28, 2020 | An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause ... |
| CVE-2020-35615 | MEDIUM | 6.3 | 0.4% | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. A missing token check in the emailexport feature of com_privacy... |
| CVE-2020-35614 | MEDIUM | 5.3 | 1.1% | Dec 28, 2020 | An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration a... |
| CVE-2020-35613 | CRITICAL | 9.8 | 28.4% | Dec 28, 2020 | An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injectio... |
| CVE-2020-35612 | HIGH | 7.5 | 1.6% | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validatio... |
| CVE-2020-35611 | HIGH | 7.5 | 1.3% | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the... |
| CVE-2020-35610 | HIGH | 7.5 | 1.3% | Dec 28, 2020 | An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the ac... |
| CVE-2020-26290 | CRITICAL | 9.6 | 1.0% | Dec 28, 2020 | Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulner... |
| CVE-2020-25507 | HIGH | 7.8 | 0.5% | Dec 28, 2020 | An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivi... |
| CVE-2020-14273 | HIGH | 7.5 | 1.2% | Dec 28, 2020 | HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its publ... |
| CVE-2020-27837 | MEDIUM | 6.4 | 0.2% | Dec 28, 2020 | A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it pos... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now