2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36563MEDIUM5.3XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs...
CVE-2020-36562HIGH7.5Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of servic...
CVE-2020-36636MEDIUM6.1A vulnerability classified as problematic has been found in OpenMRS Admin UI Module up to 1.4.x. Affected is the functio...
CVE-2020-36635MEDIUM5.4A vulnerability was found in OpenMRS Appointment Scheduling Module up to 1.12.x. It has been classified as problematic. ...
CVE-2020-36569CRITICAL9.1Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 ...
CVE-2020-36568HIGH7.5Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource ...
CVE-2020-36566CRITICAL9.1Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten...
CVE-2020-36564HIGH7.5Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed,...
CVE-2020-36561CRITICAL9.1Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten...
CVE-2020-36560CRITICAL9.1Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten...
CVE-2020-36559HIGH7.5Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to re...
CVE-2020-36567HIGH7.5Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbi...
CVE-2020-36626MEDIUM6.1A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add...
CVE-2020-36634MEDIUM5.4A vulnerability classified as problematic has been found in Indeed Engineering util up to 1.0.33. Affected is the functi...
CVE-2020-36633MEDIUM6.5A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function...
CVE-2020-28191HIGH8.8The console in Togglz before 2.9.4 allows CSRF.
CVE-2020-24600CRITICAL9.8Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.
CVE-2020-11101CRITICAL9.8Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can ...
CVE-2020-10650HIGH8.1A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to pe...
CVE-2020-12069HIGH7.8In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system sto...
CVE-2020-12067HIGH7.5In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed b...
CVE-2020-36632CRITICAL9.8A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unfla...
CVE-2020-36631CRITICAL9.8A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerabi...
CVE-2020-36630CRITICAL9.8A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler...
CVE-2020-36629HIGH7.5A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpath...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now