2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24146 | HIGH | 8.1 | 1.7% | Jul 7, 2021 | Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized us... |
| CVE-2020-24144 | HIGH | 8.6 | 2.0% | Jul 7, 2021 | Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker g... |
| CVE-2020-24143 | HIGH | 7.5 | 2.0% | Jul 7, 2021 | Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker... |
| CVE-2020-26763 | HIGH | 7.5 | 0.8% | Jul 5, 2021 | The Rocket.Chat desktop application 2.17.11 opens external links without user interaction. |
| CVE-2020-23219 | HIGH | 8.8 | 1.6% | Jul 1, 2021 | Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" fi... |
| CVE-2020-4902 | HIGH | 8.8 | 1.0% | Jul 1, 2021 | IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could sen... |
| CVE-2020-27362 | HIGH | 8.8 | 1.3% | Jul 1, 2021 | An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user... |
| CVE-2020-27361 | HIGH | 7.5 | 6.7% | Jul 1, 2021 | An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within... |
| CVE-2020-9158 | HIGH | 7.5 | 0.7% | Jul 1, 2021 | There is a Missing Cryptographic Step vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability ... |
| CVE-2020-36407 | HIGH | 8.8 | 1.4% | Jul 1, 2021 | libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid. |
| CVE-2020-36406 | HIGH | 8.8 | 1.5% | Jul 1, 2021 | uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTre... |
| CVE-2020-36405 | HIGH | 7.8 | 1.1% | Jul 1, 2021 | Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken. |
| CVE-2020-36404 | HIGH | 7.8 | 1.1% | Jul 1, 2021 | Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl. |
| CVE-2020-36403 | HIGH | 8.8 | 1.6% | Jul 1, 2021 | HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read). |
| CVE-2020-36402 | HIGH | 7.8 | 1.0% | Jul 1, 2021 | Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf68... |
| CVE-2020-36401 | HIGH | 7.8 | 1.0% | Jul 1, 2021 | mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free). |
| CVE-2020-21394 | HIGH | 8.8 | 1.2% | Jun 29, 2021 | SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename paramet... |
| CVE-2020-7870 | HIGH | 7.2 | 0.7% | Jun 29, 2021 | A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to i... |
| CVE-2020-7869 | HIGH | 8.8 | 1.6% | Jun 29, 2021 | An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker t... |
| CVE-2020-23715 | HIGH | 8.6 | 1.7% | Jun 28, 2021 | Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download. |
| CVE-2020-4610 | HIGH | 7.8 | 0.2% | Jun 25, 2021 | IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due ... |
| CVE-2020-4609 | HIGH | 7.8 | 0.3% | Jun 25, 2021 | IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by ... |
| CVE-2020-17759 | HIGH | 8.8 | 2.5% | Jun 24, 2021 | An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers fo... |
| CVE-2020-4945 | HIGH | 8.1 | 1.0% | Jun 24, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite ar... |
| CVE-2020-21785 | HIGH | 8.8 | 2.7% | Jun 24, 2021 | In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now