2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13438MEDIUM6.5ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.
CVE-2020-13435MEDIUM5.5SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
CVE-2020-13434MEDIUM5.5SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
CVE-2020-13433CRITICAL9.8Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
CVE-2020-13430MEDIUM6.1Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
CVE-2020-13429MEDIUM5.4legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (...
CVE-2020-13425HIGH7.1TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a...
CVE-2020-13424MEDIUM6.5The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
CVE-2020-13417CRITICAL9.8An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CV...
CVE-2020-13416MEDIUM6.5An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is no...
CVE-2020-13415HIGH7.5An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity...
CVE-2020-13414HIGH7.5An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
CVE-2020-13413MEDIUM5.3An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API,...
CVE-2020-13412HIGH8.8An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token ...
CVE-2020-12397MEDIUM4.3By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address t...
CVE-2020-13398HIGH8.3An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_...
CVE-2020-13397MEDIUM5.5An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security...
CVE-2020-13396HIGH7.1An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_rea...
CVE-2020-13394CRITICAL9.8An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42...
CVE-2020-13393CRITICAL9.8An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42...
CVE-2020-13392CRITICAL9.8An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42...
CVE-2020-13391CRITICAL9.8An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42...
CVE-2020-13390CRITICAL9.8An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42...
CVE-2020-13389CRITICAL9.8An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42...
CVE-2020-13388CRITICAL9.8An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Pyt...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now