2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-19303HIGH7.8An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a ...
CVE-2020-26806HIGH8.8admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in r...
CVE-2020-26565HIGH7.5ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. Thi...
CVE-2020-22761HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
CVE-2020-20698HIGH7.2A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modificatio...
CVE-2020-18157HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.
CVE-2020-16839HIGH7.5On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be chan...
CVE-2020-14999HIGH7.5A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Window...
CVE-2020-11511HIGH8.1The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP ...
CVE-2020-10590HIGH7.5Replicated Classic 2.x versions have an improperly secured API that exposes sensitive data from the Replicated Admin Con...
CVE-2020-5353HIGH8.8The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for N...
CVE-2020-5351HIGH7.5Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that...
CVE-2020-26180HIGH8.8Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an ...
CVE-2020-18430HIGH7.5tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to...
CVE-2020-18428HIGH7.5tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to...
CVE-2020-18173HIGH7.8A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.
CVE-2020-18171HIGH8.8TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed cr...
CVE-2020-18169HIGH7.8A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate ...
CVE-2020-12681HIGH7.5Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/co...
CVE-2020-22284HIGH7.5A buffer overflow vulnerability in the zepif_linkoutput() function of Free Software Foundation lwIP git head version and...
CVE-2020-22283HIGH7.5A buffer overflow vulnerability in the icmp6_send_response_with_addrs_and_netif() function of Free Software Foundation l...
CVE-2020-7389HIGH7.2Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS command...
CVE-2020-5316HIGH7.8Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home...
CVE-2020-19499HIGH8.8An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Servic...
CVE-2020-19498HIGH8.8Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibl...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now