2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10806CRITICAL9.8eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 20...
CVE-2020-10803MEDIUM5.4In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code c...
CVE-2020-10802HIGH8In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain par...
CVE-2020-10804HIGH8In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current...
CVE-2020-10800HIGH8.1lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data...
CVE-2020-10799CRITICAL9.8The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
CVE-2020-8140MEDIUM6.7A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client wit...
CVE-2020-8139MEDIUM6.5A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be do...
CVE-2020-8138MEDIUM6.5A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side ...
CVE-2020-10194MEDIUM6.5cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any ...
CVE-2020-8883MEDIUM4.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P...
CVE-2020-8882HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8881HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8880HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8879MEDIUM4.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P...
CVE-2020-8878HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2020-8877MEDIUM4.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio P...
CVE-2020-8137CRITICAL9.8Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be contr...
CVE-2020-8136HIGH7.5Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing ...
CVE-2020-8135CRITICAL9.8The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attack...
CVE-2020-8134HIGH8.1Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external netw...
CVE-2020-7961CRITICAL9.8Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c...
CVE-2020-10558MEDIUM6.5The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to...
CVE-2020-9425HIGH7.5An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved...
CVE-2020-10792HIGH7.5openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placin...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now