2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10938CRITICAL9.8GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in m...
CVE-2020-10385MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1....
CVE-2020-1747CRITICAL9.8A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code...
CVE-2020-10934HIGH7.2Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.
CVE-2020-10931HIGH7.5Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary pr...
CVE-2020-9359MEDIUM5.3KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
CVE-2020-1744MEDIUM5.6A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post log...
CVE-2020-10684HIGH7.1A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, w...
CVE-2020-10570MEDIUM6.1The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attacker...
CVE-2020-5252MEDIUM4.1The command-line "safety" package for Python has a potential security issue. There are two Python characteristics that a...
CVE-2020-1944CRITICAL9.8There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling at...
CVE-2020-10879CRITICAL9.8rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nod...
CVE-2020-10875HIGH7.5Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Ser...
CVE-2020-8868CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve ...
CVE-2020-8866MEDIUM6.5This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmai...
CVE-2020-8865MEDIUM6.3This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webma...
CVE-2020-8864HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86...
CVE-2020-8863HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86...
CVE-2020-8859HIGH7.5This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ELOG Ele...
CVE-2020-6967CRITICAL9.8In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platfor...
CVE-2020-10874HIGH7.5Motorola FX9500 devices allow remote attackers to read database files.
CVE-2020-7482MEDIUM6.1A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andov...
CVE-2020-7481MEDIUM6.1A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andov...
CVE-2020-7480CRITICAL9.8A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versi...
CVE-2020-7479HIGH7.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the se...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now