2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-24146HIGH8.1Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized us...
CVE-2020-24144HIGH8.6Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker g...
CVE-2020-24143HIGH7.5Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker...
CVE-2020-26763HIGH7.5The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
CVE-2020-23219HIGH8.8Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" fi...
CVE-2020-4902HIGH8.8IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could sen...
CVE-2020-27362HIGH8.8An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user...
CVE-2020-27361HIGH7.5An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within...
CVE-2020-9158HIGH7.5There is a Missing Cryptographic Step vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability ...
CVE-2020-36407HIGH8.8libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.
CVE-2020-36406HIGH8.8uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTre...
CVE-2020-36405HIGH7.8Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken.
CVE-2020-36404HIGH7.8Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl.
CVE-2020-36403HIGH8.8HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).
CVE-2020-36402HIGH7.8Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf68...
CVE-2020-36401HIGH7.8mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
CVE-2020-21394HIGH8.8SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename paramet...
CVE-2020-7870HIGH7.2A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to i...
CVE-2020-7869HIGH8.8An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker t...
CVE-2020-23715HIGH8.6Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.
CVE-2020-4610HIGH7.8IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due ...
CVE-2020-4609HIGH7.8IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by ...
CVE-2020-17759HIGH8.8An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers fo...
CVE-2020-4945HIGH8.1IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite ar...
CVE-2020-21785HIGH8.8In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now