2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-21830HIGH8.8A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.
CVE-2020-21827HIGH7.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode...
CVE-2020-21819HIGH8.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.
CVE-2020-21818HIGH8.8A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.
CVE-2020-21816HIGH8.8A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.
CVE-2020-21814HIGH8.8A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.
CVE-2020-21813HIGH7.8A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.
CVE-2020-27833HIGH7.1A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by us...
CVE-2020-24119HIGH7.1A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
CVE-2020-4985HIGH7.5IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameter...
CVE-2020-27185HIGH7.5Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully ex...
CVE-2020-27150HIGH7.5In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of...
CVE-2020-27020HIGH7.5Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially all...
CVE-2020-23996HIGH8.8A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to exe...
CVE-2020-27823HIGH7.8A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJ...
CVE-2020-21342HIGH7.5Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
CVE-2020-12967HIGH7.2The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code executio...
CVE-2020-36197HIGH8.8An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, th...
CVE-2020-27840HIGH7.5A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause in...
CVE-2020-28393HIGH7.5An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSP...
CVE-2020-25242HIGH7.5A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET...
CVE-2020-18964HIGH8.8Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, whic...
CVE-2020-27246HIGH8.8An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The...
CVE-2020-27245HIGH8.8An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The...
CVE-2020-27244HIGH8.8An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now