2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36563 | MEDIUM | 5.3 | 0.3% | Dec 28, 2022 | XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs... |
| CVE-2020-36562 | HIGH | 7.5 | 0.8% | Dec 28, 2022 | Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of servic... |
| CVE-2020-36636 | MEDIUM | 6.1 | 0.9% | Dec 27, 2022 | A vulnerability classified as problematic has been found in OpenMRS Admin UI Module up to 1.4.x. Affected is the functio... |
| CVE-2020-36635 | MEDIUM | 5.4 | 0.9% | Dec 27, 2022 | A vulnerability was found in OpenMRS Appointment Scheduling Module up to 1.12.x. It has been classified as problematic. ... |
| CVE-2020-36569 | CRITICAL | 9.1 | 0.8% | Dec 27, 2022 | Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 ... |
| CVE-2020-36568 | HIGH | 7.5 | 1.5% | Dec 27, 2022 | Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource ... |
| CVE-2020-36566 | CRITICAL | 9.1 | 1.0% | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten... |
| CVE-2020-36564 | HIGH | 7.5 | 0.7% | Dec 27, 2022 | Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed,... |
| CVE-2020-36561 | CRITICAL | 9.1 | 1.3% | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten... |
| CVE-2020-36560 | CRITICAL | 9.1 | 1.2% | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten... |
| CVE-2020-36559 | HIGH | 7.5 | 1.1% | Dec 27, 2022 | Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to re... |
| CVE-2020-36567 | HIGH | 7.5 | 1.4% | Dec 27, 2022 | Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbi... |
| CVE-2020-36626 | MEDIUM | 6.1 | 0.6% | Dec 27, 2022 | A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add... |
| CVE-2020-36634 | MEDIUM | 5.4 | 0.5% | Dec 27, 2022 | A vulnerability classified as problematic has been found in Indeed Engineering util up to 1.0.33. Affected is the functi... |
| CVE-2020-36633 | MEDIUM | 6.5 | 0.3% | Dec 27, 2022 | A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function... |
| CVE-2020-28191 | HIGH | 8.8 | 0.4% | Dec 26, 2022 | The console in Togglz before 2.9.4 allows CSRF. |
| CVE-2020-24600 | CRITICAL | 9.8 | 0.9% | Dec 26, 2022 | Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request. |
| CVE-2020-11101 | CRITICAL | 9.8 | 0.9% | Dec 26, 2022 | Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can ... |
| CVE-2020-10650 | HIGH | 8.1 | 3.3% | Dec 26, 2022 | A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to pe... |
| CVE-2020-12069 | HIGH | 7.8 | 0.2% | Dec 26, 2022 | In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system sto... |
| CVE-2020-12067 | HIGH | 7.5 | 0.5% | Dec 26, 2022 | In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed b... |
| CVE-2020-36632 | CRITICAL | 9.8 | 1.1% | Dec 25, 2022 | A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unfla... |
| CVE-2020-36631 | CRITICAL | 9.8 | 0.7% | Dec 25, 2022 | A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerabi... |
| CVE-2020-36630 | CRITICAL | 9.8 | 0.7% | Dec 25, 2022 | A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler... |
| CVE-2020-36629 | HIGH | 7.5 | 0.8% | Dec 25, 2022 | A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpath... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now