2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8175MEDIUM5.5Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using...
CVE-2020-8174HIGH8.1napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
CVE-2020-15945MEDIUM5.5Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) bec...
CVE-2020-14725MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...
CVE-2020-15932HIGH8.8Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.
CVE-2020-8326HIGH7.8An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that cou...
CVE-2020-8317HIGH7.8A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allo...
CVE-2020-15860CRITICAL9.9Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an ...
CVE-2020-14307MEDIUM6.5A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where Sess...
CVE-2020-14297MEDIUM6.5A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction o...
CVE-2020-15778HIGH7.4scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick charac...
CVE-2020-14175MEDIUM5.4Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or Java...
CVE-2020-15924HIGH7.5There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is req...
CVE-2020-15923HIGH7.5Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
CVE-2020-15922CRITICAL9.8There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)...
CVE-2020-15921CRITICAL9.8Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric...
CVE-2020-15920CRITICAL9.8There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi...
CVE-2020-15919MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
CVE-2020-15918MEDIUM5.4Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
CVE-2020-7520MEDIUM4.7A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Updat...
CVE-2020-7519HIGH7.5A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could al...
CVE-2020-7518HIGH7.5A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allo...
CVE-2020-7517MEDIUM5.5A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older...
CVE-2020-7516HIGH7.8A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and pri...
CVE-2020-7515HIGH7.8A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now