2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1787 | MEDIUM | 6.6 | 0.3% | Jan 9, 2020 | HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. T... |
| CVE-2020-5308 | MEDIUM | 6.1 | 1.3% | Jan 9, 2020 | PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode ... |
| CVE-2020-6632 | MEDIUM | 6.1 | 0.7% | Jan 9, 2020 | In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAcce... |
| CVE-2020-6631 | MEDIUM | 5.5 | 0.8% | Jan 9, 2020 | An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_proces... |
| CVE-2020-6630 | MEDIUM | 5.5 | 0.8% | Jan 9, 2020 | An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_dat... |
| CVE-2020-6629 | MEDIUM | 6.5 | 1.3% | Jan 9, 2020 | Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c. |
| CVE-2020-5205 | MEDIUM | 5.4 | 0.8% | Jan 9, 2020 | In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attac... |
| CVE-2020-6615 | MEDIUM | 6.5 | 1.5% | Jan 8, 2020 | GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated... |
| CVE-2020-6611 | MEDIUM | 6.5 | 1.5% | Jan 8, 2020 | GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c. |
| CVE-2020-6610 | MEDIUM | 6.5 | 1.4% | Jan 8, 2020 | GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c. |
| CVE-2020-6583 | MEDIUM | 6.1 | 0.7% | Jan 8, 2020 | BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can e... |
| CVE-2020-0008 | MEDIUM | 4.7 | 0.1% | Jan 8, 2020 | In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race con... |
| CVE-2020-0007 | MEDIUM | 5.5 | 0.2% | Jan 8, 2020 | In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. Th... |
| CVE-2020-0006 | MEDIUM | 6.5 | 0.8% | Jan 8, 2020 | In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uni... |
| CVE-2020-0004 | MEDIUM | 5.5 | 0.1% | Jan 8, 2020 | In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture ... |
| CVE-2020-0003 | MEDIUM | 6.7 | 0.1% | Jan 8, 2020 | In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulne... |
| CVE-2020-0009 | MEDIUM | 5.5 | 0.7% | Jan 8, 2020 | In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This... |
| CVE-2020-6163 | MEDIUM | 6.1 | 0.7% | Jan 8, 2020 | The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySug... |
| CVE-2020-5842 | MEDIUM | 6.1 | 1.8% | Jan 7, 2020 | Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. ... |
| CVE-2020-5393 | MEDIUM | 6.1 | 0.7% | Jan 7, 2020 | In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS. |
| CVE-2020-5843 | MEDIUM | 4.8 | 0.5% | Jan 7, 2020 | Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen. |
| CVE-2020-5513 | MEDIUM | 6.8 | 25.8% | Jan 6, 2020 | Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal. |
| CVE-2020-5512 | MEDIUM | 6.8 | 18.9% | Jan 6, 2020 | Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal. |
| CVE-2020-5191 | MEDIUM | 6.1 | 5.5% | Jan 6, 2020 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities. |
| CVE-2020-5306 | MEDIUM | 4.8 | 1.1% | Jan 5, 2020 | Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now