2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25375MEDIUM5.4Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name ...
CVE-2020-22158MEDIUM6.1MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has...
CVE-2020-8817HIGH8.1Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata.
CVE-2020-12789HIGH7.5The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
CVE-2020-12788HIGH7.5CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power anal...
CVE-2020-12787HIGH7.5Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to appl...
CVE-2020-11684CRITICAL9.1AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control ...
CVE-2020-11683MEDIUM6.8A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical acces...
CVE-2020-25540HIGH7.5ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on ...
CVE-2020-24660CRITICAL9.8An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access cont...
CVE-2020-7807MEDIUM5.5A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTR...
CVE-2020-21733MEDIUM6.1Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.
CVE-2020-21732MEDIUM6.1Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code t...
CVE-2020-21731MEDIUM6.1Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?use...
CVE-2020-25291HIGH7.8GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in ...
CVE-2020-25289MEDIUM5.5The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Man...
CVE-2020-25287HIGH7.2Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any fil...
CVE-2020-25286MEDIUM5.3In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in t...
CVE-2020-25285MEDIUM6.4A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local...
CVE-2020-25284MEDIUM4.1The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking...
CVE-2020-25283CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers...
CVE-2020-25282CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Inte...
CVE-2020-25281HIGH7.5An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sen...
CVE-2020-25280MEDIUM6.8An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated ...
CVE-2020-25279CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseb...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now