2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-19229CRITICAL9.8Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deseria...
CVE-2020-28062HIGH7.2An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getLi...
CVE-2020-25691HIGH7.5A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a ...
CVE-2020-14479MEDIUM5.3Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper...
CVE-2020-35501LOW3.4A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly n...
CVE-2020-24771HIGH7.5Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
CVE-2020-24770CRITICAL9.8SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2020-24769CRITICAL9.8SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands...
CVE-2020-21554HIGH8.1A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could ...
CVE-2020-20096MEDIUM6.5Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to...
CVE-2020-20095MEDIUM6.5iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which re...
CVE-2020-20094MEDIUM6.5Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages t...
CVE-2020-20093MEDIUM6.5The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly...
CVE-2020-24772HIGH8.8In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that ...
CVE-2020-26008HIGH7.8The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file up...
CVE-2020-26007HIGH7.8An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitra...
CVE-2020-25197HIGH8.8A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware v...
CVE-2020-25193MEDIUM5.3By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions...
CVE-2020-25184MEDIUM5.5Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same ...
CVE-2020-25182MEDIUM6.7Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled ...
CVE-2020-25180MEDIUM6.5Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is requir...
CVE-2020-25178HIGH8.8ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communic...
CVE-2020-25176CRITICAL9.8Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform...
CVE-2020-16232CRITICAL9.8In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project ...
CVE-2020-15388MEDIUM6.5A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now