2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14073 | MEDIUM | 5.4 | 2.9% | Jun 23, 2020 | XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can c... |
| CVE-2020-13157 | MEDIUM | 6.5 | 0.6% | Jun 23, 2020 | modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=... |
| CVE-2020-13156 | MEDIUM | 6.5 | 0.6% | Jun 23, 2020 | modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=u... |
| CVE-2020-13155 | HIGH | 8.8 | 0.7% | Jun 23, 2020 | clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.p... |
| CVE-2020-7668 | HIGH | 7.5 | 1.3% | Jun 23, 2020 | In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in z... |
| CVE-2020-7664 | HIGH | 7.5 | 1.4% | Jun 23, 2020 | In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in ... |
| CVE-2020-4188 | MEDIUM | 5.3 | 1.1% | Jun 23, 2020 | IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends o... |
| CVE-2020-11068 | HIGH | 8.8 | 0.9% | Jun 23, 2020 | In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. ... |
| CVE-2020-9438 | MEDIUM | 5.9 | 0.7% | Jun 23, 2020 | Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred w... |
| CVE-2020-14971 | HIGH | 7.8 | 0.6% | Jun 23, 2020 | Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup ... |
| CVE-2020-14965 | MEDIUM | 4.8 | 0.6% | Jun 23, 2020 | On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and c... |
| CVE-2020-4028 | MEDIUM | 5.3 | 0.9% | Jun 23, 2020 | Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to th... |
| CVE-2020-14993 | CRITICAL | 9.8 | 5.3% | Jun 23, 2020 | A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attack... |
| CVE-2020-14940 | HIGH | 7.5 | 3.6% | Jun 23, 2020 | An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading ... |
| CVE-2020-14939 | HIGH | 7.8 | 1.3% | Jun 23, 2020 | An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts th... |
| CVE-2020-14938 | CRITICAL | 9.8 | 1.4% | Jun 23, 2020 | An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It ... |
| CVE-2020-5594 | CRITICAL | 9.8 | 1.3% | Jun 23, 2020 | Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows ... |
| CVE-2020-12782 | CRITICAL | 9.8 | 1.9% | Jun 23, 2020 | Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the ... |
| CVE-2020-4033 | MEDIUM | 6.5 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with session... |
| CVE-2020-4032 | MEDIUM | 4.3 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients w... |
| CVE-2020-4031 | HIGH | 7.5 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility ... |
| CVE-2020-4030 | MEDIUM | 6.5 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks ... |
| CVE-2020-14946 | MEDIUM | 4.3 | 7.7% | Jun 22, 2020 | downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e... |
| CVE-2020-14945 | HIGH | 8.8 | 11.4% | Jun 22, 2020 | A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an auth... |
| CVE-2020-14944 | CRITICAL | 9.8 | 6.3% | Jun 22, 2020 | Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now