2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-8818HIGH8.1An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in t...
CVE-2020-9385HIGH7.5A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upc...
CVE-2020-9381HIGH7.5controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/w...
CVE-2020-1937HIGH8.8Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run m...
CVE-2020-9369HIGH7.5Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files,...
CVE-2020-5245HIGH8.8Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privilege...
CVE-2020-5244HIGH7.5In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Aut...
CVE-2020-9365HIGH7.5An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function i...
CVE-2020-9363HIGH7.8The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects End...
CVE-2020-9362HIGH7.8The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. Th...
CVE-2020-8131HIGH7.5Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem a...
CVE-2020-5187HIGH8.8DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
CVE-2020-9354HIGH7.5An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functional...
CVE-2020-9353HIGH7.5An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functional...
CVE-2020-9341HIGH8.8CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&...
CVE-2020-9340HIGH7.2fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter.
CVE-2020-8813HIGH8.8graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a...
CVE-2020-8862HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-26...
CVE-2020-8861HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-13...
CVE-2020-8860HIGH8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Fir...
CVE-2020-9330HIGH8.8Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind cred...
CVE-2020-9327HIGH7.5In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault ...
CVE-2020-7907HIGH7.5In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
CVE-2020-6842HIGH7.2D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell...
CVE-2020-5534HIGH8Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arb...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now