2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28905 | HIGH | 8.8 | 26.2% | May 24, 2021 | Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via... |
| CVE-2020-23768 | HIGH | 7.5 | 1.0% | May 21, 2021 | An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interfa... |
| CVE-2020-23765 | HIGH | 7.2 | 1.1% | May 21, 2021 | A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If a... |
| CVE-2020-36332 | HIGH | 7.5 | 2.0% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memor... |
| CVE-2020-27212 | HIGH | 7 | 0.3% | May 21, 2021 | STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP)... |
| CVE-2020-27209 | HIGH | 7.5 | 1.5% | May 20, 2021 | The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversar... |
| CVE-2020-18220 | HIGH | 7.5 | 0.4% | May 20, 2021 | Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not... |
| CVE-2020-35580 | HIGH | 7.5 | 14.0% | May 20, 2021 | A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated us... |
| CVE-2020-21057 | HIGH | 8.1 | 1.5% | May 20, 2021 | Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the syst... |
| CVE-2020-4850 | HIGH | 7.5 | 1.0% | May 20, 2021 | IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive i... |
| CVE-2020-24396 | HIGH | 7.5 | 1.8% | May 20, 2021 | homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware ima... |
| CVE-2020-25709 | HIGH | 7.5 | 2.9% | May 18, 2021 | A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s... |
| CVE-2020-24755 | HIGH | 7.8 | 0.6% | May 17, 2021 | In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. ... |
| CVE-2020-21844 | HIGH | 8.8 | 1.5% | May 17, 2021 | GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is... |
| CVE-2020-21843 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318. |
| CVE-2020-21842 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode... |
| CVE-2020-21831 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:... |
| CVE-2020-18198 | HIGH | 8.8 | 0.9% | May 17, 2021 | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete speci... |
| CVE-2020-18195 | HIGH | 8.8 | 0.9% | May 17, 2021 | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a spe... |
| CVE-2020-21841 | HIGH | 8.8 | 1.4% | May 17, 2021 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135. |
| CVE-2020-21840 | HIGH | 8.8 | 1.4% | May 17, 2021 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985. |
| CVE-2020-21838 | HIGH | 8.8 | 1.4% | May 17, 2021 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:... |
| CVE-2020-21836 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:... |
| CVE-2020-21833 | HIGH | 8.8 | 1.4% | May 17, 2021 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:... |
| CVE-2020-21832 | HIGH | 8.8 | 1.2% | May 17, 2021 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now