2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14073MEDIUM5.4XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can c...
CVE-2020-13157MEDIUM6.5modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=...
CVE-2020-13156MEDIUM6.5modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=u...
CVE-2020-13155HIGH8.8clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.p...
CVE-2020-7668HIGH7.5In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in z...
CVE-2020-7664HIGH7.5In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in ...
CVE-2020-4188MEDIUM5.3IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends o...
CVE-2020-11068HIGH8.8In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. ...
CVE-2020-9438MEDIUM5.9Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred w...
CVE-2020-14971HIGH7.8Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup ...
CVE-2020-14965MEDIUM4.8On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and c...
CVE-2020-4028MEDIUM5.3Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to th...
CVE-2020-14993CRITICAL9.8A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attack...
CVE-2020-14940HIGH7.5An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading ...
CVE-2020-14939HIGH7.8An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts th...
CVE-2020-14938CRITICAL9.8An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It ...
CVE-2020-5594CRITICAL9.8Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows ...
CVE-2020-12782CRITICAL9.8Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the ...
CVE-2020-4033MEDIUM6.5In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with session...
CVE-2020-4032MEDIUM4.3In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients w...
CVE-2020-4031HIGH7.5In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility ...
CVE-2020-4030MEDIUM6.5In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks ...
CVE-2020-14946MEDIUM4.3downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e...
CVE-2020-14945HIGH8.8A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an auth...
CVE-2020-14944CRITICAL9.8Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now