2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25755HIGH8.8An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /insta...
CVE-2020-25754HIGH7.5An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication tha...
CVE-2020-22201HIGH8.8phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/produc...
CVE-2020-24939HIGH7.5Prototype pollution in Stampit supermixer 1.0.3 allows an attacker to modify the prototype of a base object which can va...
CVE-2020-20444HIGH7.2Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infecte...
CVE-2020-12988HIGH7.5A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker t...
CVE-2020-12986HIGH7.8An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code exec...
CVE-2020-12985HIGH7.8An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of pri...
CVE-2020-12983HIGH7.8An out of bounds write vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privileges or d...
CVE-2020-12982HIGH7.8An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privile...
CVE-2020-12981HIGH7.8An insufficient input validation in the AMD Graphics Driver for Windows 10 may allow unprivileged users to unload the dr...
CVE-2020-12980HIGH7.8An out of bounds write and read vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privil...
CVE-2020-7860HIGH7.8UnEGG v0.5 and eariler versions have a Integer overflow vulnerability, triggered when the user opens a malformed specifi...
CVE-2020-13663HIGH8.8Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-...
CVE-2020-23322HIGH7.5There is an Assertion in 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context...
CVE-2020-23320HIGH7.5There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' in parser_parse_function_argume...
CVE-2020-23319HIGH7.5There is an Assertion in '(flags >> CBC_STACK_ADJUST_SHIFT) >= CBC_STACK_ADJUST_BASE || (CBC_STACK_ADJUST_BASE - (flags ...
CVE-2020-23314HIGH7.5There is an Assertion 'block_found' failed at js-parser-statm.c:2003 parser_parse_try_statement_end in JerryScript 2.2.0...
CVE-2020-23313HIGH7.5There is an Assertion 'scope_stack_p > context_p->scope_stack_p' failed at js-scanner-util.c:2510 in scanner_literal_is_...
CVE-2020-23312HIGH7.5There is an Assertion 'context.status_flags & PARSER_SCANNING_SUCCESSFUL' failed at js-parser.c:2185 in parser_parse_sou...
CVE-2020-23311HIGH7.5There is an Assertion 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p-...
CVE-2020-23310HIGH7.5There is an Assertion 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at js-parser-statm.c:733 in...
CVE-2020-23309HIGH7.5There is an Assertion 'context_p->stack_depth == context_p->context_stack_depth' failed at js-parser-statm.c:2756 in par...
CVE-2020-23308HIGH7.5There is an Assertion 'context_p->stack_top_uint8 == LEXER_EXPRESSION_START' at js-parser-expr.c:3565 in parser_parse_ex...
CVE-2020-24671HIGH8.8Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now