2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12857HIGH7.5Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re...
CVE-2020-12856CRITICAL9.8OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Andro...
CVE-2020-13128HIGH7.5An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) acce...
CVE-2020-4345LOW3.3IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local use...
CVE-2020-13126CRITICAL9.9An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in ...
CVE-2020-13125MEDIUM6.5An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the w...
CVE-2020-13121MEDIUM6.1Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
CVE-2020-13118CRITICAL9.8An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community...
CVE-2020-13111HIGH7.5NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly valida...
CVE-2020-13110HIGH7.8The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of ...
CVE-2020-13109CRITICAL9.8Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted...
CVE-2020-8149CRITICAL9.8Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before ve...
CVE-2020-1758MEDIUM5.9A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while se...
CVE-2020-13093MEDIUM5.3iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.
CVE-2020-13092CRITICAL9.8scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to ...
CVE-2020-13091CRITICAL9.8pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() fun...
CVE-2020-12872MEDIUM5.5yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet3...
CVE-2020-12889CRITICAL9.8MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.
CVE-2020-12888MEDIUM5.3The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
CVE-2020-12798HIGH7.8Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command...
CVE-2020-12651CRITICAL9.8SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow b...
CVE-2020-12834CRITICAL9.8eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSO...
CVE-2020-12685MEDIUM6.1XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote...
CVE-2020-11526LOW2.2libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
CVE-2020-11525LOW2.2libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now