2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-26252HIGH7.2OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vul...
CVE-2020-27859HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ESMPRO Man...
CVE-2020-27858HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2...
CVE-2020-6024HIGH7.8Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and...
CVE-2020-28483HIGH7.1This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's ...
CVE-2020-28452HIGH8.8This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package c...
CVE-2020-25682HIGH8.1A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names...
CVE-2020-25681HIGH8.1A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorte...
CVE-2020-14360HIGH7.8A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead ...
CVE-2020-4983HIGH7.8IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to subm...
CVE-2020-4921HIGH8.8IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL s...
CVE-2020-4688HIGH7.8IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unpri...
CVE-2020-35217HIGH8.8Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF toke...
CVE-2020-19364HIGH8.8OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
CVE-2020-19360HIGH7.5Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a fil...
CVE-2020-27264HIGH8.8In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and...
CVE-2020-14409HIGH7.8SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_...
CVE-2020-4881HIGH7.5IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server h...
CVE-2020-27733HIGH8.8Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmvi...
CVE-2020-28482HIGH8.8This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the...
CVE-2020-28479HIGH7.5The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.
CVE-2020-23342HIGH8.8A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
CVE-2020-28478HIGH7.5This affects the package gsap before 3.6.0.
CVE-2020-28477HIGH7.5This affects all versions of package immer.
CVE-2020-36193HIGH7.5Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of sym...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now