2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11958HIGH7.8re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.
CVE-2020-9279CRITICAL9.8An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login ...
CVE-2020-9278CRITICAL9.1An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by...
CVE-2020-9277CRITICAL9.8An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modul...
CVE-2020-9276HIGH8.8An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests sup...
CVE-2020-9275CRITICAL9.8An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote...
CVE-2020-11944MEDIUM6.1Abe (aka bitcoin-abe) through 0.7.2, and 0.8pre, allows XSS in __call__ in abe.py because the PATH_INFO environment vari...
CVE-2020-11010HIGH8.8In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when fi...
CVE-2020-11946HIGH7.5Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
CVE-2020-9445MEDIUM6.1Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
CVE-2020-9444MEDIUM6.1Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
CVE-2020-9070MEDIUM5.5Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulne...
CVE-2020-3946HIGH7.5InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 ...
CVE-2020-1803MEDIUM5.3Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3...
CVE-2020-10935MEDIUM5.4Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
CVE-2020-11753HIGH8.8An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user wi...
CVE-2020-5293MEDIUM6.5In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations...
CVE-2020-5288MEDIUM6.5"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The p...
CVE-2020-5287MEDIUM6.5In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is...
CVE-2020-5286MEDIUM6.1In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is...
CVE-2020-5285MEDIUM6.1In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed...
CVE-2020-5279MEDIUM6.5In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for ...
CVE-2020-5278MEDIUM6.1In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1...
CVE-2020-5276MEDIUM6.1In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter...
CVE-2020-5272MEDIUM6.1In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` pa...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now