2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36698HIGH8.8The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions...
CVE-2020-27636CRITICAL9.1In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
CVE-2020-27635CRITICAL9.1In PicoTCP 1.7.0, TCP ISNs are improperly random.
CVE-2020-27634CRITICAL9.1In Contiki 4.5, TCP ISNs are improperly random.
CVE-2020-27633CRITICAL9.1In FNET 4.6.3, TCP ISNs are improperly random.
CVE-2020-27631CRITICAL9.8In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
CVE-2020-27630CRITICAL9.8In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
CVE-2020-27213HIGH7.5An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connecti...
CVE-2020-18336HIGH7.4Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive informati...
CVE-2020-24089MEDIUM5.5An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a ...
CVE-2020-36766LOW3.3An issue was discovered in the Linux kernel before 5.8.6. drivers/media/cec/core/cec-api.c leaks one byte of kernel memo...
CVE-2020-19559CRITICAL9.8An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted pay...
CVE-2020-19323HIGH7.5An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing...
CVE-2020-19320CRITICAL9.8Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.
CVE-2020-19319CRITICAL9.8Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
CVE-2020-19318HIGH8.8Buffer Overflow vulnerability in D-Link DIR-605L, hardware version AX, firmware version 1.17beta and below, allows autho...
CVE-2020-24088HIGH7.8An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escal...
CVE-2020-10132MEDIUM6.1SearchBlox before Version 9.1 is vulnerable to cross-origin resource sharing misconfiguration.
CVE-2020-10131CRITICAL9.8SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
CVE-2020-10130HIGH8.8SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super adm...
CVE-2020-10129HIGH8.8SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality.
CVE-2020-10128MEDIUM5.4SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input paramet...
CVE-2020-35593HIGH7.8BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.
CVE-2020-22612CRITICAL9.8Installer RCE on settings file write in MyBB before 1.8.22.
CVE-2020-18912CRITICAL9.8An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now