2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-5504HIGH8.8In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could ...
CVE-2020-6168HIGH7.6A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with bas...
CVE-2020-6167HIGH8.8A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable main...
CVE-2020-1925HIGH7.5Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location head...
CVE-2020-6628HIGH8.8Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.
CVE-2020-6625HIGH7.1jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
CVE-2020-6624HIGH7.1jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
CVE-2020-6623HIGH8.8stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
CVE-2020-6622HIGH8.8stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.
CVE-2020-6621HIGH8.8stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.
CVE-2020-6620HIGH8.8stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
CVE-2020-6619HIGH8.8stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
CVE-2020-6618HIGH8.8stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
CVE-2020-6617HIGH8.8stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
CVE-2020-6614HIGH8.1GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
CVE-2020-6613HIGH8.1GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
CVE-2020-6612HIGH8.1GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
CVE-2020-6609HIGH8.8GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
CVE-2020-0002HIGH8.8In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead...
CVE-2020-0001HIGH7.8In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to loc...
CVE-2020-5511HIGH8.8PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administ...
CVE-2020-5183HIGH7.5FTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string ...
CVE-2020-5846HIGH8.8An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm...
CVE-2020-5204HIGH8.8In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer tha...
CVE-2020-5515HIGH7.2Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now