2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15307MEDIUM6.1Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to...
CVE-2020-15049HIGH8.8An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggli...
CVE-2020-14482HIGH7.8Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow...
CVE-2020-15087HIGH8.8In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. T...
CVE-2020-15085MEDIUM6.1In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the ...
CVE-2020-13095HIGH8.8Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the use...
CVE-2020-4044HIGH7.8The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious pa...
CVE-2020-15084CRITICAL9.1In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration i...
CVE-2020-9483HIGH7.5**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is ...
CVE-2020-14957HIGH7.8In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) ...
CVE-2020-14956HIGH7.8In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) ...
CVE-2020-7816HIGH7.8A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticate...
CVE-2020-15415CRITICAL9.8On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote...
CVE-2020-15412MEDIUM4.3An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding ...
CVE-2020-15411CRITICAL9.8An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the atta...
CVE-2020-15401MEDIUM4.4IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious fl...
CVE-2020-15400MEDIUM4.3CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
CVE-2020-15397HIGH7.8HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileg...
CVE-2020-15396HIGH7.8In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. B...
CVE-2020-5603HIGH7.5Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Conf...
CVE-2020-5602HIGH7.5Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configura...
CVE-2020-5601HIGH8.8Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspe...
CVE-2020-5588MEDIUM4.9Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain uninten...
CVE-2020-5587MEDIUM6.5Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vecto...
CVE-2020-5586MEDIUM4.8Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now