2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-29321HIGH7.5The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmw...
CVE-2020-36141HIGH8.8BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpe...
CVE-2020-27302HIGH8A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "me...
CVE-2020-27301HIGH8A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AE...
CVE-2020-7469HIGH7.5In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 1...
CVE-2020-36382HIGH7.5OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase v...
CVE-2020-36009HIGH7.5OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.
CVE-2020-36008HIGH8.1OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability.
CVE-2020-35970HIGH7.5An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows...
CVE-2020-28469HIGH7.5This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure con...
CVE-2020-4495HIGH8.8IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused b...
CVE-2020-25362HIGH7.5The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injec...
CVE-2020-24862HIGH7.5The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind ...
CVE-2020-24870HIGH8.8Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.
CVE-2020-35514HIGH7An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacke...
CVE-2020-14380HIGH7.5An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to...
CVE-2020-14326HIGH7.5A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, le...
CVE-2020-10771HIGH7.1A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects ...
CVE-2020-22036HIGH8.8A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c, which might l...
CVE-2020-22035HIGH8.8A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in get_block_row at libavfilter/vf_bm3d.c, which might l...
CVE-2020-26670HIGH8.8A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute ...
CVE-2020-26668HIGH8.8A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an...
CVE-2020-17541HIGH8.8Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a ...
CVE-2020-4520HIGH8.8IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the a...
CVE-2020-4300HIGH8.2IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now