2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29135MEDIUM4.1cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
CVE-2020-29133MEDIUM6.1jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename...
CVE-2020-12262MEDIUM5.4Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= ...
CVE-2020-29130MEDIUM4.3slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even i...
CVE-2020-29129MEDIUM4.3ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if...
CVE-2020-26936HIGH8.8Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.
CVE-2020-29043HIGH7.5An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?to...
CVE-2020-29042LOW3.7An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of c...
CVE-2020-29065Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2020-27663MEDIUM4.3In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows...
CVE-2020-27662MEDIUM4.3In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an atta...
CVE-2020-27207HIGH7.5Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite...
CVE-2020-13886MEDIUM5.3Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?pag...
CVE-2020-7779HIGH7.5All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted in...
CVE-2020-7778HIGH7.3This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an ...
CVE-2020-29128CRITICAL9.8petl before 1.68, in some configurations, allows resolution of entities in an XML document.
CVE-2020-27255HIGH7.5A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a re...
CVE-2020-27253HIGH7.5A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could ...
CVE-2020-27251CRITICAL9.8A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a re...
CVE-2020-25653MEDIUM6.3A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw ...
CVE-2020-25652MEDIUM5.5A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be establish...
CVE-2020-25651MEDIUM6.4A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in t...
CVE-2020-29074HIGH8.8scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
CVE-2020-14190HIGH7.5Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-suppl...
CVE-2020-14191HIGH7.5Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a De...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now