2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15637LOW3.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomP...
CVE-2020-15636CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, ...
CVE-2020-15635HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-15634MEDIUM6.3This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-15630HIGH7.8This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P...
CVE-2020-15629HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-15532MEDIUM6.5Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denia...
CVE-2020-15531HIGH8.8Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remot...
CVE-2020-15151HIGH8OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Inte...
CVE-2020-15149CRITICAL9.9NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to ch...
CVE-2020-15146HIGH8.8In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression...
CVE-2020-15143HIGH8.8In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expressio...
CVE-2020-15119MEDIUM5.4In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerously...
CVE-2020-13826HIGH8.8A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute ar...
CVE-2020-13825MEDIUM6.1A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HT...
CVE-2020-23574MEDIUM6.5When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uplo...
CVE-2020-9724HIGH7.8Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability. Successful exploitation co...
CVE-2020-9723HIGH7.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9722HIGH7.8Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9721HIGH7.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9720HIGH7.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9719HIGH7.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9718HIGH7.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9717HIGH7.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...
CVE-2020-9716HIGH7.5Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now