2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-26158CRITICAL9.6Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This ...
CVE-2020-26157CRITICAL9.6Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code ...
CVE-2020-26154CRITICAL9.8url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC fil...
CVE-2020-26042CRITICAL9.8An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php
CVE-2020-26041CRITICAL9.8An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php
CVE-2020-25763CRITICAL9.8Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers ...
CVE-2020-25762CRITICAL9.1An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v...
CVE-2020-21526CRITICAL9.8An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory tr...
CVE-2020-21524CRITICAL9.1There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the backgrou...
CVE-2020-21523CRITICAL9.8A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl fi...
CVE-2020-21522CRITICAL9.8An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can ove...
CVE-2020-20800CRITICAL9.8An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndat...
CVE-2020-19672CRITICAL9.8Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface...
CVE-2020-15487CRITICAL9.8Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protec...
CVE-2020-12506CRITICAL9.1Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the se...
CVE-2020-15208CRITICAL9.8In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of ...
CVE-2020-15207CRITICAL9In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative value...
CVE-2020-15205CRITICAL9.8In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGr...
CVE-2020-15202CRITICAL9In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argu...
CVE-2020-15196CRITICAL9.9In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate ...
CVE-2020-25147CRITICAL9.8An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection ...
CVE-2020-25132CRITICAL9.8An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection ...
CVE-2020-15374CRITICAL9.8Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instan...
CVE-2020-15373CRITICAL9.8Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 ver...
CVE-2020-15371CRITICAL9.8Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code inject...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now