2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-1760MEDIUM6.1A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw...
CVE-2020-12054MEDIUM6.1The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also a...
CVE-2020-11945CRITICAL9.8An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gai...
CVE-2020-11940HIGH7.5In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positione...
CVE-2020-11939CRITICAL9.8In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlle...
CVE-2020-11806MEDIUM5.9In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the v...
CVE-2020-5571HIGH7.5SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQU...
CVE-2020-12079CRITICAL10Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron con...
CVE-2020-12077HIGH8.8The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions wi...
CVE-2020-12076HIGH8.8The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One ...
CVE-2020-12075HIGH8.8The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
CVE-2020-12074HIGH8.8The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import admi...
CVE-2020-12073HIGH8.8The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action...
CVE-2020-12071MEDIUM4.8Anchor 0.12.7 allows admins to cause XSS via crafted post content.
CVE-2020-8833MEDIUM4.7Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible ...
CVE-2020-8831MEDIUM5.5Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the a...
CVE-2020-7350HIGH7.8Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the...
CVE-2020-8867HIGH7.5This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foun...
CVE-2020-10915CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4....
CVE-2020-10914CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4....
CVE-2020-10913HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0...
CVE-2020-10912HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0...
CVE-2020-10911HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0...
CVE-2020-10910HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0...
CVE-2020-10909HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now