2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14528MEDIUM6.1Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Acces...
CVE-2020-14527MEDIUM5.9Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Acces...
CVE-2020-8203HIGH7.4Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
CVE-2020-8178CRITICAL9.8Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
CVE-2020-15572HIGH7.5Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor ...
CVE-2020-9496MEDIUM6.1XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
CVE-2020-15700MEDIUM6.3An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer c...
CVE-2020-15699MEDIUM5.3An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result i...
CVE-2020-15698MEDIUM5.3An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Re...
CVE-2020-15697MEDIUM4.3An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified b...
CVE-2020-15696MEDIUM6.1An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random...
CVE-2020-15695MEDIUM6.3An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy ca...
CVE-2020-13923MEDIUM5.3IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
CVE-2020-7292MEDIUM4.3Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attac...
CVE-2020-5765MEDIUM5.4Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during sc...
CVE-2020-4100MEDIUM4.4"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which comp...
CVE-2020-14511CRITICAL9.8Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server o...
CVE-2020-14503CRITICAL9.8Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this...
CVE-2020-14501CRITICAL9.8Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successfu...
CVE-2020-14499HIGH7.5Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this v...
CVE-2020-14507CRITICAL9.8Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an at...
CVE-2020-14505CRITICAL9.8Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command ...
CVE-2020-14497CRITICAL9.8Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use ...
CVE-2020-1481HIGH8.8A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source cod...
CVE-2020-1469HIGH7.5A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now