2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35654HIGH8.8In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain...
CVE-2020-35653HIGH7.1In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stri...
CVE-2020-26050HIGH7.8SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SY...
CVE-2020-16146HIGH7.5Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x thr...
CVE-2020-27059HIGH7.8In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's finger...
CVE-2020-13559HIGH7.5A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simul...
CVE-2020-35701HIGH8.8An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote aut...
CVE-2020-27293HIGH7.8Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which ...
CVE-2020-27291HIGH7.8Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while processing project f...
CVE-2020-27289HIGH7.8Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project fil...
CVE-2020-27287HIGH7.8Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project ...
CVE-2020-27281HIGH7.8A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when proces...
CVE-2020-27277HIGH7.8Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files...
CVE-2020-27275HIGH7.8Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project fi...
CVE-2020-23960HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attac...
CVE-2020-17534HIGH7There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in ...
CVE-2020-35483HIGH7.8AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the applic...
CVE-2020-2508HIGH7.2A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows...
CVE-2020-26118HIGH8.8In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentic...
CVE-2020-23630HIGH8.8A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
CVE-2020-17509HIGH7.5ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or ...
CVE-2020-17508HIGH7.5The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic S...
CVE-2020-5146HIGH7.2A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection usi...
CVE-2020-5018HIGH7.5IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of suc...
CVE-2020-16043HIGH8.8Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass d...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now