2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10180CRITICAL9.8The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects ve...
CVE-2020-5250MEDIUM6.3In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the ...
CVE-2020-9418HIGH7.8An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attack...
CVE-2020-8994MEDIUM6.8An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing t...
CVE-2020-4278HIGH7.8IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user...
CVE-2020-10174HIGH7init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the pr...
CVE-2020-9544HIGH7.5An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authenticat...
CVE-2020-9402HIGH8.8Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a ...
CVE-2020-10173HIGH8.8Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabiliti...
CVE-2020-9380CRITICAL9.8IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.
CVE-2020-9370CRITICAL9.1HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
CVE-2020-10107MEDIUM5.4PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCo...
CVE-2020-10106CRITICAL9.8PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in in...
CVE-2020-10105MEDIUM5.3An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS...
CVE-2020-10104MEDIUM4.3An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user ...
CVE-2020-10103MEDIUM5.4An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t...
CVE-2020-10102MEDIUM5.3An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would ...
CVE-2020-10101HIGH7.5An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sen...
CVE-2020-10100MEDIUM6.5An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with s...
CVE-2020-10099MEDIUM5.4An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t...
CVE-2020-10098MEDIUM5.4An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t...
CVE-2020-10097MEDIUM5.3An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal app...
CVE-2020-10096HIGH7.5An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memor...
CVE-2020-8660MEDIUM5.3CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) ...
CVE-2020-8664MEDIUM5.3CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same s...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now