2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3481HIGH7.5A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could a...
CVE-2020-15123CRITICAL9.3In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the co...
CVE-2020-15121CRITICAL9.6In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the p...
CVE-2020-15118MEDIUM5.4In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagt...
CVE-2020-15111MEDIUM5.4In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is...
CVE-2020-15053MEDIUM6.1An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time ...
CVE-2020-15052HIGH7.5An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alia...
CVE-2020-8214HIGH7.5A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
CVE-2020-7680MEDIUM6.1docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a...
CVE-2020-12031HIGH7.8In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a lo...
CVE-2020-12028HIGH8.1In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to int...
CVE-2020-12027MEDIUM4.3All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote,...
CVE-2020-8215HIGH8.8A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitra...
CVE-2020-8205HIGH7.5The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, w...
CVE-2020-14494CRITICAL9.8OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide ...
CVE-2020-14491MEDIUM6.5OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may al...
CVE-2020-14485CRITICAL9.8OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted...
CVE-2020-14484CRITICAL9.8OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, whi...
CVE-2020-12029HIGH7.8All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, un...
CVE-2020-4527MEDIUM5.9IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t...
CVE-2020-4466MEDIUM6.5IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attacker could cause a denial of service due t...
CVE-2020-4361MEDIUM4.3IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addres...
CVE-2020-15009HIGH7.8AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs ...
CVE-2020-15842HIGH8.1Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, ...
CVE-2020-15841HIGH8.8Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now