2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24654LOW3.3In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as de...
CVE-2020-24553MEDIUM6.1Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a ...
CVE-2020-24030CRITICAL9.8ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access...
CVE-2020-24029CRITICAL9.8Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can b...
CVE-2020-24028HIGH8.8ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, passwor...
CVE-2020-23830HIGH7.1A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 a...
CVE-2020-15811MEDIUM6.5An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitt...
CVE-2020-15810MEDIUM6.5An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggl...
CVE-2020-14209HIGH8.8Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio...
CVE-2020-13802CRITICAL9.8Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specificat...
CVE-2020-12621MEDIUM6.1The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-c...
CVE-2020-25079HIGH8.8An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.c...
CVE-2020-25078HIGH7.5An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate...
CVE-2020-16150MEDIUM5.5A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23...
CVE-2020-24604MEDIUM6.1A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows rem...
CVE-2020-24602MEDIUM6.1Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute ar...
CVE-2020-24601MEDIUM6.1In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious...
CVE-2020-17458MEDIUM5.4A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field.
CVE-2020-16602HIGH8.1Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra...
CVE-2020-24355CRITICAL9.8Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insec...
CVE-2020-5622HIGH7.5Shadankun Server Security Type (excluding normal blocking method types) Ver.1.5.3 and earlier allows remote attackers to...
CVE-2020-25073MEDIUM5.3FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apa...
CVE-2020-8341LOW2.4In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient prot...
CVE-2020-8335MEDIUM6.8The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS ...
CVE-2020-24955HIGH7.8SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivilege...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now