2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35704MEDIUM5.4Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.
CVE-2020-35702HIGH7.8DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE...
CVE-2020-26282CRITICAL10BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data ...
CVE-2020-29474CRITICAL9.8EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access usin...
CVE-2020-29472CRITICAL9.8EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admi...
CVE-2020-29247MEDIUM4.8WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in ...
CVE-2020-28912HIGH7With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivi...
CVE-2020-11093HIGH7.5Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperle...
CVE-2020-35693HIGH8.8On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Lo...
CVE-2020-24658HIGH7.8Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overfl...
CVE-2020-9202MEDIUM4.4There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to th...
CVE-2020-9201MEDIUM6.5There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software re...
CVE-2020-9200HIGH7.8There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege ...
CVE-2020-9137MEDIUM6.7There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 an...
CVE-2020-9120HIGH7.5CloudEngine 1800V versions V100R019C10SPC500 has a resource management error vulnerability. Remote unauthorized attacker...
CVE-2020-9119MEDIUM6.2There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to p...
CVE-2020-35680HIGH7.5smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of ...
CVE-2020-35679HIGH7.5smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very signif...
CVE-2020-35659MEDIUM6.1The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indir...
CVE-2020-27729MEDIUM6.1In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an u...
CVE-2020-27728HIGH7.5On BIG-IP ASM & Advanced WAF versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, under certain conditions, Ana...
CVE-2020-27727MEDIUM4.9On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administra...
CVE-2020-27726MEDIUM6.1In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-sit...
CVE-2020-27723HIGH7.5In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess requests may lead to a ...
CVE-2020-27722MEDIUM6.5In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin doe...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now