2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5612MEDIUM6.1Cross-site scripting vulnerability in KonaWiki 2.2.0 and earlier allows remote attackers to execute an arbitrary script ...
CVE-2020-6098HIGH7.5An exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A special...
CVE-2020-13997HIGH7.5In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and v...
CVE-2020-13971MEDIUM5.4In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG image...
CVE-2020-13970HIGH8.8Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature....
CVE-2020-11476HIGH7.2Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
CVE-2020-11474HIGH7.8NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.
CVE-2020-10985MEDIUM4.8Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.
CVE-2020-10984HIGH8.8Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.
CVE-2020-10983MEDIUM4.9Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.
CVE-2020-10982MEDIUM4.9Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.
CVE-2020-16094HIGH7.5In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because ...
CVE-2020-5377CRITICAL9.1Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. ...
CVE-2020-15899HIGH7.5Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
CVE-2020-15419HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0...
CVE-2020-15418HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0...
CVE-2020-15417MEDIUM6.3This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-15416HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700...
CVE-2020-10930MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG...
CVE-2020-10929HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-10928HIGH8.4This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-10927HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-10926HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-10925HIGH8.8This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i...
CVE-2020-10924HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now