2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13593HIGH8.8The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R...
CVE-2020-12829LOW3.8In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the...
CVE-2020-12646MEDIUM5.4OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
CVE-2020-12645CRITICAL9.8OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed va...
CVE-2020-12644MEDIUM5OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
CVE-2020-12643MEDIUM4.3OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing ...
CVE-2020-11618HIGH7.8THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start ...
CVE-2020-11617MEDIUM5.9The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the S...
CVE-2020-24115CRITICAL9.8In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
CVE-2020-4492MEDIUM5.5IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a deni...
CVE-2020-15020MEDIUM5.4An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stor...
CVE-2020-25033MEDIUM6.1The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= re...
CVE-2020-25032HIGH7.5An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to...
CVE-2020-25031HIGH7.8checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 execu...
CVE-2020-24104MEDIUM6.1XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials wit...
CVE-2020-8097HIGH7.8An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Sec...
CVE-2020-24223MEDIUM6.1Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
CVE-2020-24917MEDIUM6.1osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php...
CVE-2020-8244MEDIUM6.5A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply...
CVE-2020-14352HIGH8A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to ...
CVE-2020-7712HIGH7.2This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
CVE-2020-24972HIGH8.8The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code ...
CVE-2020-24928MEDIUM5.3managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origi...
CVE-2020-24898MEDIUM6.5The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Tabl...
CVE-2020-24897HIGH8.9The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now