2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11528HIGH7.5bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a b...
CVE-2020-11527HIGH7.5In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to r...
CVE-2020-11518CRITICAL9.8Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
CVE-2020-5348HIGH7.8Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system m...
CVE-2020-5347HIGH7.5Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error co...
CVE-2020-8147CRITICAL9.8Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that...
CVE-2020-8143MEDIUM6.1An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn14...
CVE-2020-8142MEDIUM6.8A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoa...
CVE-2020-8639HIGH8.8An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute ar...
CVE-2020-8638CRITICAL9.8A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php v...
CVE-2020-8637CRITICAL9.8A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes...
CVE-2020-6994CRITICAL9.8A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vul...
CVE-2020-7008HIGH7.5VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly v...
CVE-2020-7004HIGH8.8VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE dire...
CVE-2020-7000HIGH7.5VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cr...
CVE-2020-10601HIGH7.8VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions wh...
CVE-2020-10599CRITICAL9.8VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited...
CVE-2020-10960MEDIUM5.3In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is...
CVE-2020-10689MEDIUM6.8A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An...
CVE-2020-4273HIGH7.8IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to e...
CVE-2020-11501HIGH7.4GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) bec...
CVE-2020-11500HIGH7.5Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all pa...
CVE-2020-5283LOW3.5ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this v...
CVE-2020-11499MEDIUM6.1Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request...
CVE-2020-11498HIGH8.8Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now