2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35738MEDIUM6.1WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a mallo...
CVE-2020-35736HIGH7.5GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path....
CVE-2020-29156MEDIUM5.3The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the...
CVE-2020-29250MEDIUM6.1CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.
CVE-2020-29249MEDIUM6.1CXUUCMS V3 allows class="layui-input" XSS.
CVE-2020-29299HIGH7.2Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change a...
CVE-2020-29204MEDIUM6.1XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/j...
CVE-2020-35729CRITICAL9.8KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
CVE-2020-35728HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-35448LOW3.3An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1....
CVE-2020-8290HIGH7.8Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit`...
CVE-2020-8289HIGH7.8Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validat...
CVE-2020-7845CRITICAL9.8Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsi...
CVE-2020-35678MEDIUM6.1Autobahn|Python before 20.12.3 allows redirect header injection.
CVE-2020-35245CRITICAL9.8Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
CVE-2020-35244CRITICAL9.8Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
CVE-2020-35243CRITICAL9.8Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
CVE-2020-35242CRITICAL9.8Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAnd...
CVE-2020-29203CRITICAL9.8struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT.
CVE-2020-28759MEDIUM5.5The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don'...
CVE-2020-35364CRITICAL9.8Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a proce...
CVE-2020-35362HIGH7.5DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow rem...
CVE-2020-35284HIGH7.5Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable pa...
CVE-2020-35450HIGH7.5Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.
CVE-2020-35359HIGH7.5Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the con...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now