2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12242HIGH7.8Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in ...
CVE-2020-12138HIGH8.8AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of se...
CVE-2020-12133CRITICAL9.8The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of...
CVE-2020-12120HIGH7.5The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such a...
CVE-2020-11822MEDIUM6.1In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus...
CVE-2020-11821MEDIUM5.3In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hash...
CVE-2020-11817CRITICAL9.8In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As...
CVE-2020-11810LOW3.7An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using...
CVE-2020-11415MEDIUM4.9An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can r...
CVE-2020-9489MEDIUM5.5A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can a...
CVE-2020-12272MEDIUM5.3OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about t...
CVE-2020-11420MEDIUM6.5UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exp...
CVE-2020-12274CRITICAL9.8In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on ...
CVE-2020-12273HIGH7.5In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
CVE-2020-12052MEDIUM6.1Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVE-2020-10997MEDIUM6.5Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may i...
CVE-2020-10996HIGH8.1An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static tr...
CVE-2020-10664HIGH7.5The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference.
CVE-2020-10647Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-12271CRITICAL9.8A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as e...
CVE-2020-12270MEDIUM6.5React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote...
CVE-2020-12268CRITICAL9.8jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
CVE-2020-12267CRITICAL9.8setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
CVE-2020-12265CRITICAL9.8The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when...
CVE-2020-12254HIGH7.8Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlin...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now