2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29321 | HIGH | 7.5 | 1.4% | Jun 4, 2021 | The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmw... |
| CVE-2020-36141 | HIGH | 8.8 | 1.3% | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpe... |
| CVE-2020-27302 | HIGH | 8 | 2.0% | Jun 4, 2021 | A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "me... |
| CVE-2020-27301 | HIGH | 8 | 2.0% | Jun 4, 2021 | A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AE... |
| CVE-2020-7469 | HIGH | 7.5 | 1.2% | Jun 4, 2021 | In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 1... |
| CVE-2020-36382 | HIGH | 7.5 | 1.9% | Jun 4, 2021 | OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase v... |
| CVE-2020-36009 | HIGH | 7.5 | 1.3% | Jun 3, 2021 | OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability. |
| CVE-2020-36008 | HIGH | 8.1 | 1.1% | Jun 3, 2021 | OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability. |
| CVE-2020-35970 | HIGH | 7.5 | 1.3% | Jun 3, 2021 | An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows... |
| CVE-2020-28469 | HIGH | 7.5 | 4.5% | Jun 3, 2021 | This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure con... |
| CVE-2020-4495 | HIGH | 8.8 | 2.6% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused b... |
| CVE-2020-25362 | HIGH | 7.5 | 2.1% | Jun 2, 2021 | The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injec... |
| CVE-2020-24862 | HIGH | 7.5 | 2.1% | Jun 2, 2021 | The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind ... |
| CVE-2020-24870 | HIGH | 8.8 | 1.6% | Jun 2, 2021 | Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp. |
| CVE-2020-35514 | HIGH | 7 | 0.2% | Jun 2, 2021 | An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacke... |
| CVE-2020-14380 | HIGH | 7.5 | 0.8% | Jun 2, 2021 | An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to... |
| CVE-2020-14326 | HIGH | 7.5 | 1.2% | Jun 2, 2021 | A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, le... |
| CVE-2020-10771 | HIGH | 7.1 | 0.4% | Jun 2, 2021 | A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects ... |
| CVE-2020-22036 | HIGH | 8.8 | 1.7% | Jun 1, 2021 | A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might l... |
| CVE-2020-22035 | HIGH | 8.8 | 1.2% | Jun 1, 2021 | A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might l... |
| CVE-2020-26670 | HIGH | 8.8 | 1.8% | Jun 1, 2021 | A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute ... |
| CVE-2020-26668 | HIGH | 8.8 | 1.4% | Jun 1, 2021 | A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an... |
| CVE-2020-17541 | HIGH | 8.8 | 2.7% | Jun 1, 2021 | Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a ... |
| CVE-2020-4520 | HIGH | 8.8 | 2.7% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the a... |
| CVE-2020-4300 | HIGH | 8.2 | 4.0% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now