2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27787MEDIUM5.5A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input...
CVE-2020-14394LOW3.2An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer ...
CVE-2020-1756HIGH7.2In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin...
CVE-2020-1755MEDIUM5.3In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to...
CVE-2020-14379MEDIUM5.6A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading ...
CVE-2020-14322HIGH7.5In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitig...
CVE-2020-14321HIGH8.8In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role wi...
CVE-2020-14320MEDIUM6.1In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflect...
CVE-2020-10728HIGH7.8A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all us...
CVE-2020-10710MEDIUM4.4A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satell...
CVE-2020-23622HIGH7.5An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service ...
CVE-2020-21642CRITICAL9.8Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus befo...
CVE-2020-21641HIGH7.5Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote a...
CVE-2020-21365HIGH7.5Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose...
CVE-2020-1754MEDIUM4.3In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' ...
CVE-2020-1691MEDIUM5.4In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stor...
CVE-2020-7795CRITICAL9.8The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
CVE-2020-28453CRITICAL9.8This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
CVE-2020-28451CRITICAL9.8This affects the package image-tiler before 2.0.2.
CVE-2020-28437CRITICAL9.8This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index...
CVE-2020-28434CRITICAL9.8This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
CVE-2020-28433CRITICAL9.8This affects all versions of package node-latex-pdf.
CVE-2020-28425CRITICAL9.8This affects all versions of package curljs.
CVE-2020-28424CRITICAL9.8This affects all versions of package s3-kilatstorage.
CVE-2020-28423CRITICAL9.8This affects all versions of package monorepo-build.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now