2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9411CRITICAL9.8The file transfer component of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for IBM i contains a vu...
CVE-2020-13160CRITICAL9.8AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut...
CVE-2020-9792MEDIUM4.6A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macO...
CVE-2020-3882MEDIUM6.5This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously cr...
CVE-2020-13266MEDIUM4.3Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permi...
CVE-2020-13980MEDIUM4.8OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upl...
CVE-2020-13978HIGH7.2Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk...
CVE-2020-13977MEDIUM4.9Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration s...
CVE-2020-13976HIGH8.8An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary comman...
CVE-2020-10761MEDIUM5An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. Thi...
CVE-2020-10757HIGH7.8A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allow...
CVE-2020-5589HIGH8.8SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X...
CVE-2020-13974HIGH7.8An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_as...
CVE-2020-13973MEDIUM6.1OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls anoth...
CVE-2020-13965MEDIUM6.1An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta...
CVE-2020-13964MEDIUM6.1An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows...
CVE-2020-13962HIGH7.5Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error qu...
CVE-2020-13844MEDIUM5.5Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow un...
CVE-2020-4041MEDIUM6.1In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inj...
CVE-2020-4040MEDIUM4.3Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be gen...
CVE-2020-4038HIGH7.4GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulne...
CVE-2020-13960HIGH7.5D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search p...
CVE-2020-13885HIGH7.8Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during ...
CVE-2020-13884HIGH7.8Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows loc...
CVE-2020-13428HIGH7.8A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media p...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now