2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-19137HIGH7.5Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via...
CVE-2020-27942HIGH7.8A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Se...
CVE-2020-11301HIGH7.5Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosur...
CVE-2020-19769HIGH7.5A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from...
CVE-2020-19768HIGH7.5A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from...
CVE-2020-19767HIGH7.5A lack of target address verification in the destroycontract() function of 0xRACER 1.0 allows attackers to steal tokens ...
CVE-2020-19766HIGH7.5The time check operation of PepeAuctionSale 1.0 can be rendered ineffective by assigning a large number to the _duration...
CVE-2020-19765HIGH7.5An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a re...
CVE-2020-19752HIGH7.5The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
CVE-2020-19750HIGH7.5An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read.
CVE-2020-7819HIGH7.5A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthentic...
CVE-2020-19131HIGH7.5Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the...
CVE-2020-7877HIGH8.8A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' comma...
CVE-2020-13929HIGH7.5Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to...
CVE-2020-20341HIGH7.5YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
CVE-2020-20340HIGH7.5A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sens...
CVE-2020-9002HIGH7.5An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changin...
CVE-2020-9000HIGH7.5An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input...
CVE-2020-20490HIGH7.5A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS).
CVE-2020-20486HIGH7.5IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr.
CVE-2020-19047HIGH8.8Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST r...
CVE-2020-35635HIGH8.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_...
CVE-2020-35634HIGH8.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-35633HIGH8.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-18121HIGH8.8A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now