2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-27243HIGH8.8An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The...
CVE-2020-27242HIGH8.8An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The...
CVE-2020-23575HIGH7.5A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnera...
CVE-2020-28600HIGH7.8An out-of-bounds write vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12...
CVE-2020-27232HIGH8.8An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A speciall...
CVE-2020-27231HIGH8.8A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 applicat...
CVE-2020-27230HIGH8.8A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 applicat...
CVE-2020-27229HIGH8.8A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 applicat...
CVE-2020-27226HIGH8.8An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted ...
CVE-2020-19199HIGH8.8A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let ...
CVE-2020-22809HIGH7.8In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
CVE-2020-36128HIGH8.2Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment term...
CVE-2020-36126HIGH8.1Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote ...
CVE-2020-36125HIGH7.1Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidat...
CVE-2020-11295HIGH7.8Use after free in camera If the threadmanager is being cleaned up while the worker thread is processing objects in Snapd...
CVE-2020-11294HIGH7.8Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, S...
CVE-2020-11289HIGH7.8Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdrago...
CVE-2020-11288HIGH7.8Out of bound write can occur in playready while processing command due to lack of input validation in Snapdragon Auto, S...
CVE-2020-11284HIGH7.8Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the me...
CVE-2020-11274HIGH7.5Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon...
CVE-2020-11273HIGH7.5Histogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null poi...
CVE-2020-11268HIGH7.5Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of servi...
CVE-2020-23264HIGH8.8Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged...
CVE-2020-28198HIGH7The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe...
CVE-2020-18888HIGH7.5Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now