2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35738 | MEDIUM | 6.1 | 1.2% | Dec 28, 2020 | WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a mallo... |
| CVE-2020-35736 | HIGH | 7.5 | 15.4% | Dec 27, 2020 | GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.... |
| CVE-2020-29156 | MEDIUM | 5.3 | 4.0% | Dec 27, 2020 | The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the... |
| CVE-2020-29250 | MEDIUM | 6.1 | 0.7% | Dec 27, 2020 | CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php. |
| CVE-2020-29249 | MEDIUM | 6.1 | 0.7% | Dec 27, 2020 | CXUUCMS V3 allows class="layui-input" XSS. |
| CVE-2020-29299 | HIGH | 7.2 | 2.3% | Dec 27, 2020 | Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change a... |
| CVE-2020-29204 | MEDIUM | 6.1 | 0.9% | Dec 27, 2020 | XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/j... |
| CVE-2020-35729 | CRITICAL | 9.8 | 88.0% | Dec 27, 2020 | KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. |
| CVE-2020-35728 | HIGH | 8.1 | 12.5% | Dec 27, 2020 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-35448 | LOW | 3.3 | 1.3% | Dec 27, 2020 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1.... |
| CVE-2020-8290 | HIGH | 7.8 | 0.6% | Dec 27, 2020 | Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit`... |
| CVE-2020-8289 | HIGH | 7.8 | 4.7% | Dec 27, 2020 | Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validat... |
| CVE-2020-7845 | CRITICAL | 9.8 | 2.7% | Dec 27, 2020 | Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsi... |
| CVE-2020-35678 | MEDIUM | 6.1 | 1.4% | Dec 27, 2020 | Autobahn|Python before 20.12.3 allows redirect header injection. |
| CVE-2020-35245 | CRITICAL | 9.8 | 1.1% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser. |
| CVE-2020-35244 | CRITICAL | 9.8 | 1.1% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup. |
| CVE-2020-35243 | CRITICAL | 9.8 | 1.1% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb. |
| CVE-2020-35242 | CRITICAL | 9.8 | 1.1% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAnd... |
| CVE-2020-29203 | CRITICAL | 9.8 | 1.3% | Dec 26, 2020 | struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT. |
| CVE-2020-28759 | MEDIUM | 5.5 | 0.7% | Dec 26, 2020 | The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don'... |
| CVE-2020-35364 | CRITICAL | 9.8 | 1.9% | Dec 26, 2020 | Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a proce... |
| CVE-2020-35362 | HIGH | 7.5 | 1.6% | Dec 26, 2020 | DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow rem... |
| CVE-2020-35284 | HIGH | 7.5 | 1.6% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable pa... |
| CVE-2020-35450 | HIGH | 7.5 | 1.4% | Dec 26, 2020 | Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls. |
| CVE-2020-35359 | HIGH | 7.5 | 4.7% | Dec 26, 2020 | Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the con... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now