2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14194MEDIUM5.4Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
CVE-2020-12759MEDIUM6.1Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.
CVE-2020-24574HIGH7.8The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local pri...
CVE-2020-24571HIGH7.5NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.
CVE-2020-24567HIGH7.8voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file...
CVE-2020-12619MEDIUM5.9MailMate before 1.11 automatically imported S/MIME certificates and thereby silently replaced existing ones. This allowe...
CVE-2020-12618MEDIUM4.8eM Client before 7.2.33412.0 automatically imported S/MIME certificates and thereby silently replaced existing ones. Thi...
CVE-2020-24359HIGH7.5HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet i...
CVE-2020-4687MEDIUM4.3IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they...
CVE-2020-4548LOW2.7IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass...
CVE-2020-16282HIGH8.8In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged...
CVE-2020-16281HIGH7.8The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restri...
CVE-2020-16280MEDIUM5.5Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several ex...
CVE-2020-16279CRITICAL9.8The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplie...
CVE-2020-23935CRITICAL9.8Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (...
CVE-2020-23936CRITICAL9.8PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Passwo...
CVE-2020-14357Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-10283CRITICAL9.8The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to...
CVE-2020-10289HIGH8.8Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YA...
CVE-2020-8870HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8869HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-17456CRITICAL9.8SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa...
CVE-2020-15862HIGH7.8Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability ...
CVE-2020-15861HIGH7.8Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
CVE-2020-15638HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.2...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now