2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-28905HIGH8.8Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via...
CVE-2020-23768HIGH7.5An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interfa...
CVE-2020-23765HIGH7.2A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If a...
CVE-2020-36332HIGH7.5A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memor...
CVE-2020-27212HIGH7STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP)...
CVE-2020-27209HIGH7.5The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversar...
CVE-2020-18220HIGH7.5Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not...
CVE-2020-35580HIGH7.5A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated us...
CVE-2020-21057HIGH8.1Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the syst...
CVE-2020-4850HIGH7.5IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive i...
CVE-2020-24396HIGH7.5homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware ima...
CVE-2020-25709HIGH7.5A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s...
CVE-2020-24755HIGH7.8In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. ...
CVE-2020-21844HIGH8.8GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is...
CVE-2020-21843HIGH8.8A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318.
CVE-2020-21842HIGH8.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode...
CVE-2020-21831HIGH8.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:...
CVE-2020-18198HIGH8.8Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete speci...
CVE-2020-18195HIGH8.8Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a spe...
CVE-2020-21841HIGH8.8A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135.
CVE-2020-21840HIGH8.8A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985.
CVE-2020-21838HIGH8.8A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:...
CVE-2020-21836HIGH8.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:...
CVE-2020-21833HIGH8.8A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:...
CVE-2020-21832HIGH8.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now