2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14040HIGH7.5The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder ent...
CVE-2020-6869HIGH8.1All versions up to 10.06 of ZTEMarket APK are impacted by an information leak vulnerability. Due to Activity Component e...
CVE-2020-4532MEDIUM5.3IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8....
CVE-2020-9332HIGH7.8ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code...
CVE-2020-7932MEDIUM5.7OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query paramet...
CVE-2020-6752LOW3.8In OMERO before 5.6.1, group owners can access members' data in other groups.
CVE-2020-13637HIGH7.5An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms...
CVE-2020-14405MEDIUM6.5An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
CVE-2020-14404MEDIUM5.4An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
CVE-2020-14403MEDIUM5.4An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
CVE-2020-14402MEDIUM5.4An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
CVE-2020-14401MEDIUM6.5An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
CVE-2020-14400HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvnc...
CVE-2020-14399HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvnc...
CVE-2020-14398HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in li...
CVE-2020-14397HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.
CVE-2020-14396HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.
CVE-2020-14295HIGH7.2A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead...
CVE-2020-12827HIGH7.2MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML docu...
CVE-2020-10747Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-13224HIGH8.8TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3....
CVE-2020-11914MEDIUM4.3The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.
CVE-2020-11913MEDIUM5.3The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
CVE-2020-11912MEDIUM5.3The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.
CVE-2020-11911MEDIUM5.3The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now