2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16161HIGH7.5GoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_ScaledData(). Parsing malicious input can result in a...
CVE-2020-16160HIGH7.5GoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_Decompress(). Parsing malicious input can result in a...
CVE-2020-16159CRITICAL9.1GoPro gpmf-parser 1.5 has a heap out-of-bounds read and segfault in GPMF_ScaledData(). Parsing malicious input can resul...
CVE-2020-16158HIGH8.8GoPro gpmf-parser through 1.5 has a stack out-of-bounds write vulnerability in GPMF_ExpandComplexTYPE(). Parsing malicio...
CVE-2020-26891MEDIUM6.1AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET para...
CVE-2020-24266HIGH7.5An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that c...
CVE-2020-24265HIGH7.5An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorC...
CVE-2020-8929MEDIUM5.3A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker...
CVE-2020-15910MEDIUM4.7SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible...
CVE-2020-15909HIGH8.8SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Cen...
CVE-2020-13778HIGH8.8rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to li...
CVE-2020-7745HIGH7.1This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functional...
CVE-2020-13893MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to in...
CVE-2020-27197CRITICAL9.8TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an ini...
CVE-2020-1243HIGH7.8<p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific ...
CVE-2020-1167HIGH7.8<p>A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. ...
CVE-2020-1080HIGH8.8<p>An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects...
CVE-2020-1047HIGH7.8<p>An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects...
CVE-2020-17023HIGH7.8<p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'p...
CVE-2020-17022HIGH7.8<p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memo...
CVE-2020-17003HIGH7.8<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An at...
CVE-2020-16995HIGH7.8<p>An elevation of privilege vulnerability exists in Network Watcher Agent virtual machine extension for Linux. An attac...
CVE-2020-16980HIGH7.8<p>An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operatio...
CVE-2020-16978MEDIUM5.4<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a sp...
CVE-2020-16977HIGH7<p>A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads a Jupyter notebook...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now