2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11047MEDIUM5.9In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A ma...
CVE-2020-11046LOW2.2In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead t...
CVE-2020-11045LOW3.3In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client me...
CVE-2020-11044LOW2.2In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client appl...
CVE-2020-11042MEDIUM5.9In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading...
CVE-2020-7805CRITICAL9.8An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This i...
CVE-2020-7803HIGH8.8IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donw...
CVE-2020-10974HIGH7.5An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the...
CVE-2020-10973HIGH7.5An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/Ex...
CVE-2020-10972HIGH7.5An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source c...
CVE-2020-10971HIGH8.8An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will resul...
CVE-2020-7646CRITICAL9.8curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
CVE-2020-5751MEDIUM5.4Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si...
CVE-2020-5750MEDIUM6.1Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-...
CVE-2020-5749MEDIUM5.4Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si...
CVE-2020-5748MEDIUM6.1Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-...
CVE-2020-5747MEDIUM5.4Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si...
CVE-2020-5746MEDIUM5.4Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si...
CVE-2020-5745HIGH7.4Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by trickin...
CVE-2020-5744MEDIUM4.9Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files...
CVE-2020-5743MEDIUM4.3Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadat...
CVE-2020-12679MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 befor...
CVE-2020-12608HIGH7.8An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni...
CVE-2020-12448MEDIUM5.3GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
CVE-2020-11431CRITICAL9.1The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remot...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now