2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26134MEDIUM6.1Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode.
CVE-2020-26124HIGH8.8openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield PO...
CVE-2020-25741LOW3.2fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the curren...
CVE-2020-24698CRITICAL9.8An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, u...
CVE-2020-24697HIGH7.5An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, u...
CVE-2020-24696HIGH8.1An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, u...
CVE-2020-17482MEDIUM4.3An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to inser...
CVE-2020-17382HIGH7.8The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
CVE-2020-14294MEDIUM6.1An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when re...
CVE-2020-14293HIGH7.5conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacter...
CVE-2020-13168MEDIUM6.1SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
CVE-2020-12127HIGH7.5An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030...
CVE-2020-12126CRITICAL9.8Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow...
CVE-2020-12125CRITICAL9.8A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.19040...
CVE-2020-12124CRITICAL9.8A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.1...
CVE-2020-12123HIGH8.1CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely ...
CVE-2020-26540HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mech...
CVE-2020-26539CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V...
CVE-2020-26538HIGH7.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a ...
CVE-2020-26537CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outp...
CVE-2020-26536MEDIUM5.5An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PD...
CVE-2020-26535CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storag...
CVE-2020-26534CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Fie...
CVE-2020-26524MEDIUM5.3CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
CVE-2020-26523MEDIUM6.1Froala Editor before 3.2.2 allows XSS via pasted content.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now