2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13912HIGH7.3SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, b...
CVE-2020-13910CRITICAL9.1Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an in...
CVE-2020-13909CRITICAL9.8The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x ser...
CVE-2020-13904MEDIUM5.5FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavf...
CVE-2020-13902HIGH7.1ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c duri...
CVE-2020-13897MEDIUM6.1HESK before 3.1.10 allows reflected XSS.
CVE-2020-13895HIGH8.8Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA sign...
CVE-2020-13894HIGH7.5handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the sa...
CVE-2020-13890MEDIUM5.4The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
CVE-2020-13889MEDIUM5.4showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
CVE-2020-13883MEDIUM6.7In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Manage...
CVE-2020-13881HIGH7.5In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel ...
CVE-2020-13871HIGH7.5SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions i...
CVE-2020-13865MEDIUM5.4The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author...
CVE-2020-13864MEDIUM5.4The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can...
CVE-2020-11696MEDIUM6.1In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (com...
CVE-2020-13646HIGH7.8In Cheetah free WiFi 5.1, the driver file (liebaonat.sys) allows local users to cause a denial of service (BSOD) or poss...
CVE-2020-11697MEDIUM6.1In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (commu...
CVE-2020-13870MEDIUM5.4An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
CVE-2020-13869MEDIUM5.4An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
CVE-2020-13868MEDIUM6.5An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
CVE-2020-5591HIGH7.5XACK DNS 1.11.0 to 1.11.4, 1.10.0 to 1.10.8, 1.8.0 to 1.8.23, 1.7.0 to 1.7.18, and versions before 1.7.0 allow remote at...
CVE-2020-13867MEDIUM5.5Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup fil...
CVE-2020-10071CRITICAL9.8The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer o...
CVE-2020-10070CRITICAL9.8In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execu...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now