2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14943 | MEDIUM | 5.4 | 3.7% | Jun 22, 2020 | The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cros... |
| CVE-2020-11099 | MEDIUM | 6.5 | 2.1% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipul... |
| CVE-2020-11098 | MEDIUM | 6.5 | 1.7% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with... |
| CVE-2020-11097 | MEDIUM | 5.4 | 1.5% | Jun 22, 2020 | In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside o... |
| CVE-2020-11096 | MEDIUM | 6.5 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one c... |
| CVE-2020-11095 | MEDIUM | 5.4 | 1.5% | Jun 22, 2020 | In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside o... |
| CVE-2020-14990 | HIGH | 7.1 | 0.5% | Jun 22, 2020 | IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Cl... |
| CVE-2020-14983 | CRITICAL | 9.8 | 2.2% | Jun 22, 2020 | The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading... |
| CVE-2020-12053 | CRITICAL | 9.8 | 0.7% | Jun 22, 2020 | In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoi... |
| CVE-2020-1727 | MEDIUM | 5.4 | 0.8% | Jun 22, 2020 | A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks pro... |
| CVE-2020-11989 | CRITICAL | 9.8 | 24.4% | Jun 22, 2020 | Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may caus... |
| CVE-2020-14981 | MEDIUM | 5.9 | 0.8% | Jun 22, 2020 | The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation. |
| CVE-2020-14980 | MEDIUM | 5.9 | 1.1% | Jun 22, 2020 | The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation. |
| CVE-2020-14973 | MEDIUM | 6.1 | 1.2% | Jun 22, 2020 | The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS... |
| CVE-2020-14972 | CRITICAL | 9.8 | 5.4% | Jun 22, 2020 | Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated... |
| CVE-2020-14049 | HIGH | 7.5 | 2.2% | Jun 22, 2020 | Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber... |
| CVE-2020-13480 | MEDIUM | 5.4 | 1.0% | Jun 22, 2020 | Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature. |
| CVE-2020-13427 | MEDIUM | 6.1 | 0.9% | Jun 22, 2020 | Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname... |
| CVE-2020-13426 | MEDIUM | 6.5 | 1.2% | Jun 22, 2020 | The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it pre... |
| CVE-2020-13159 | CRITICAL | 9.8 | 9.3% | Jun 22, 2020 | Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, ... |
| CVE-2020-13158 | HIGH | 7.5 | 53.5% | Jun 22, 2020 | Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parame... |
| CVE-2020-11520 | HIGH | 7.8 | 0.4% | Jun 22, 2020 | The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory ad... |
| CVE-2020-11519 | HIGH | 7.8 | 0.8% | Jun 22, 2020 | The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sect... |
| CVE-2020-10740 | HIGH | 7.5 | 1.7% | Jun 22, 2020 | A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible ... |
| CVE-2020-10736 | HIGH | 8 | 0.6% | Jun 22, 2020 | An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr d... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now