2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14943MEDIUM5.4The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cros...
CVE-2020-11099MEDIUM6.5In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipul...
CVE-2020-11098MEDIUM6.5In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with...
CVE-2020-11097MEDIUM5.4In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside o...
CVE-2020-11096MEDIUM6.5In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one c...
CVE-2020-11095MEDIUM5.4In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside o...
CVE-2020-14990HIGH7.1IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Cl...
CVE-2020-14983CRITICAL9.8The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading...
CVE-2020-12053CRITICAL9.8In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoi...
CVE-2020-1727MEDIUM5.4A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks pro...
CVE-2020-11989CRITICAL9.8Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may caus...
CVE-2020-14981MEDIUM5.9The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
CVE-2020-14980MEDIUM5.9The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
CVE-2020-14973MEDIUM6.1The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS...
CVE-2020-14972CRITICAL9.8Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated...
CVE-2020-14049HIGH7.5Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber...
CVE-2020-13480MEDIUM5.4Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
CVE-2020-13427MEDIUM6.1Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname...
CVE-2020-13426MEDIUM6.5The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it pre...
CVE-2020-13159CRITICAL9.8Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, ...
CVE-2020-13158HIGH7.5Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parame...
CVE-2020-11520HIGH7.8The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory ad...
CVE-2020-11519HIGH7.8The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sect...
CVE-2020-10740HIGH7.5A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible ...
CVE-2020-10736HIGH8An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr d...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now