2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5504 | HIGH | 8.8 | 38.8% | Jan 9, 2020 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could ... |
| CVE-2020-6168 | HIGH | 7.6 | 2.0% | Jan 9, 2020 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with bas... |
| CVE-2020-6167 | HIGH | 8.8 | 0.9% | Jan 9, 2020 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable main... |
| CVE-2020-1925 | HIGH | 7.5 | 2.8% | Jan 9, 2020 | Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location head... |
| CVE-2020-6628 | HIGH | 8.8 | 1.5% | Jan 9, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c. |
| CVE-2020-6625 | HIGH | 7.1 | 1.4% | Jan 9, 2020 | jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c. |
| CVE-2020-6624 | HIGH | 7.1 | 1.4% | Jan 9, 2020 | jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c. |
| CVE-2020-6623 | HIGH | 8.8 | 1.5% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index. |
| CVE-2020-6622 | HIGH | 8.8 | 1.4% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8. |
| CVE-2020-6621 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT. |
| CVE-2020-6620 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8. |
| CVE-2020-6619 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek. |
| CVE-2020-6618 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table. |
| CVE-2020-6617 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int. |
| CVE-2020-6614 | HIGH | 8.1 | 1.7% | Jan 8, 2020 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c. |
| CVE-2020-6613 | HIGH | 8.1 | 1.7% | Jan 8, 2020 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c. |
| CVE-2020-6612 | HIGH | 8.1 | 1.7% | Jan 8, 2020 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c. |
| CVE-2020-6609 | HIGH | 8.8 | 1.8% | Jan 8, 2020 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c. |
| CVE-2020-0002 | HIGH | 8.8 | 1.4% | Jan 8, 2020 | In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead... |
| CVE-2020-0001 | HIGH | 7.8 | 0.4% | Jan 8, 2020 | In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to loc... |
| CVE-2020-5511 | HIGH | 8.8 | 1.7% | Jan 8, 2020 | PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administ... |
| CVE-2020-5183 | HIGH | 7.5 | 2.0% | Jan 8, 2020 | FTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string ... |
| CVE-2020-5846 | HIGH | 8.8 | 1.4% | Jan 6, 2020 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm... |
| CVE-2020-5204 | HIGH | 8.8 | 1.1% | Jan 6, 2020 | In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer tha... |
| CVE-2020-5515 | HIGH | 7.2 | 26.5% | Jan 6, 2020 | Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now