2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-0123CRITICAL9.8There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID...
CVE-2020-8028CRITICAL9.3A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Se...
CVE-2020-24377CRITICAL9.6A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
CVE-2020-24376CRITICAL9.6A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2....
CVE-2020-24374CRITICAL9.6A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
CVE-2020-14517CRITICAL9.8Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 ...
CVE-2020-14509CRITICAL9.8Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mecha...
CVE-2020-25614CRITICAL9.8xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause...
CVE-2020-25412CRITICAL9.8com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code ex...
CVE-2020-14315CRITICAL9.8A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insuffi...
CVE-2020-7293CRITICAL9Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user w...
CVE-2020-23833CRITICAL9.8Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers t...
CVE-2020-23828CRITICAL9.8A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote ...
CVE-2020-24561CRITICAL9.1A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrar...
CVE-2020-15148CRITICAL10Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize(...
CVE-2020-15179CRITICAL9The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using <script> tag insid...
CVE-2020-15178CRITICAL9.3In PrestaShop contactform module (prestashop/contactform) before version 4.3.0, an attacker is able to inject JavaScript...
CVE-2020-23512CRITICAL9.8VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the ...
CVE-2020-16098CRITICAL9.8It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions ...
CVE-2020-13312CRITICAL9.8A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerabl...
CVE-2020-25576CRITICAL9.8An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandle...
CVE-2020-25575CRITICAL9.8An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some ap...
CVE-2020-25573CRITICAL9.8An issue was discovered in the linked-hash-map crate before 0.5.3 for Rust. It creates an uninitialized NonNull pointer,...
CVE-2020-13300CRITICAL10GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in ...
CVE-2020-11684CRITICAL9.1AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now