2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-15495HIGH7.8Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service ...
CVE-2020-12731HIGH7.5The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whe...
CVE-2020-15496HIGH7.8Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.
CVE-2020-36420HIGH7.5Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a mal...
CVE-2020-29157HIGH7.8An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system ...
CVE-2020-29147HIGH7.5A SQL injection vulnerability in wy_controlls/wy_side_visitor.php of Wayang-CMS v1.0 allows attackers to obtain sensitiv...
CVE-2020-25445HIGH7.8The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input ...
CVE-2020-0417HIGH7.8In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable Pend...
CVE-2020-22907HIGH7.5Stack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Den...
CVE-2020-22886HIGH7.5Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to caus...
CVE-2020-22885HIGH7.5Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to...
CVE-2020-22882HIGH7.5Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted...
CVE-2020-22876HIGH7.5Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is...
CVE-2020-28400HIGH7.5Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service conditio...
CVE-2020-19907HIGH8.8A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to e...
CVE-2020-23079HIGH7.5SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.
CVE-2020-4938HIGH8.8IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malici...
CVE-2020-7872HIGH7.8DaviewIndy v8.98.7.0 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malform...
CVE-2020-21131HIGH7.2SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.
CVE-2020-20585HIGH7.5A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database...
CVE-2020-20583HIGH7.5A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive databas...
CVE-2020-20582HIGH7.5A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to ac...
CVE-2020-28598HIGH7.8An out-of-bounds write vulnerability exists in the Admesh stl_fix_normal_directions() functionality of Prusa Research Pr...
CVE-2020-25868HIGH7.5Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote att...
CVE-2020-24149HIGH7.5Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for Wor...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now