2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27787 | MEDIUM | 5.5 | 0.4% | Aug 18, 2022 | A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input... |
| CVE-2020-14394 | LOW | 3.2 | 0.4% | Aug 17, 2022 | An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer ... |
| CVE-2020-1756 | HIGH | 7.2 | 0.9% | Aug 16, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin... |
| CVE-2020-1755 | MEDIUM | 5.3 | 0.5% | Aug 16, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to... |
| CVE-2020-14379 | MEDIUM | 5.6 | 0.2% | Aug 16, 2022 | A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading ... |
| CVE-2020-14322 | HIGH | 7.5 | 0.8% | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitig... |
| CVE-2020-14321 | HIGH | 8.8 | 16.4% | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role wi... |
| CVE-2020-14320 | MEDIUM | 6.1 | 0.6% | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflect... |
| CVE-2020-10728 | HIGH | 7.8 | 0.2% | Aug 16, 2022 | A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all us... |
| CVE-2020-10710 | MEDIUM | 4.4 | 0.2% | Aug 16, 2022 | A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satell... |
| CVE-2020-23622 | HIGH | 7.5 | 1.0% | Aug 15, 2022 | An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service ... |
| CVE-2020-21642 | CRITICAL | 9.8 | 7.7% | Aug 15, 2022 | Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus befo... |
| CVE-2020-21641 | HIGH | 7.5 | 4.3% | Aug 15, 2022 | Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote a... |
| CVE-2020-21365 | HIGH | 7.5 | 1.8% | Aug 15, 2022 | Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose... |
| CVE-2020-1754 | MEDIUM | 4.3 | 0.5% | Aug 5, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' ... |
| CVE-2020-1691 | MEDIUM | 5.4 | 0.5% | Aug 5, 2022 | In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stor... |
| CVE-2020-7795 | CRITICAL | 9.8 | 3.7% | Aug 2, 2022 | The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js. |
| CVE-2020-28453 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js. |
| CVE-2020-28451 | CRITICAL | 9.8 | 1.2% | Aug 2, 2022 | This affects the package image-tiler before 2.0.2. |
| CVE-2020-28437 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index... |
| CVE-2020-28434 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js. |
| CVE-2020-28433 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | This affects all versions of package node-latex-pdf. |
| CVE-2020-28425 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | This affects all versions of package curljs. |
| CVE-2020-28424 | CRITICAL | 9.8 | 0.7% | Aug 2, 2022 | This affects all versions of package s3-kilatstorage. |
| CVE-2020-28423 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | This affects all versions of package monorepo-build. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now