2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15889CRITICAL9.8Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient...
CVE-2020-15888HIGH8.8Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffe...
CVE-2020-15724HIGH7.8In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a loca...
CVE-2020-15723HIGH7.8In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome...
CVE-2020-15722HIGH7.8In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privileg...
CVE-2020-15102MEDIUM6.5In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to c...
CVE-2020-14063MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows u...
CVE-2020-15879HIGH7.5Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe,...
CVE-2020-15877HIGH8.8An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guar...
CVE-2020-15873MEDIUM6.5In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST ...
CVE-2020-15859LOW3.3QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the da...
CVE-2020-15866CRITICAL9.8mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrec...
CVE-2020-12499HIGH7.3In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on imp...
CVE-2020-12432MEDIUM6.1The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a...
CVE-2020-4125HIGH8.1Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL enviro...
CVE-2020-13932MEDIUM6.1In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or top...
CVE-2020-6103CRITICAL9.9An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64....
CVE-2020-6102CRITICAL9.9An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64....
CVE-2020-6101CRITICAL9.9An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64....
CVE-2020-6100CRITICAL9.9An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially...
CVE-2020-3442MEDIUM5.7The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initi...
CVE-2020-1776MEDIUM4.3When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not b...
CVE-2020-15852HIGH7.8An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attac...
CVE-2020-6872MEDIUM6.1The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes thr...
CVE-2020-6871CRITICAL9.8The server management software module of ZTE has an authentication issue vulnerability, which allows users to skip the a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now