2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6059HIGH8.2An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A ...
CVE-2020-6058CRITICAL9.1An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A ...
CVE-2020-7221HIGH7.8mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root becau...
CVE-2020-4163HIGH7.2IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user...
CVE-2020-3939MEDIUM6.1SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Cross-Site Scripting(XSS), personal informa...
CVE-2020-3938HIGH7.5SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to laun...
CVE-2020-3937HIGH7.5SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries ...
CVE-2020-5236MEDIUM6.5Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a head...
CVE-2020-5235CRITICAL9.8There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is ...
CVE-2020-8597CRITICAL9.8eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
CVE-2020-8592CRITICAL9.8eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password featu...
CVE-2020-8591CRITICAL9.8eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r re...
CVE-2020-8549MEDIUM6.1Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious ...
CVE-2020-8548MEDIUM6.1massCode 1.0.0-alpha.6 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegrati...
CVE-2020-5182MEDIUM6.5The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link t...
CVE-2020-4224MEDIUM5.5IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain direc...
CVE-2020-8547CRITICAL9.8phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which m...
CVE-2020-8545HIGH7.5Global.py in AIL framework 2.8 allows path traversal.
CVE-2020-8510CRITICAL9.8An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of...
CVE-2020-7993MEDIUM4.3Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a mo...
CVE-2020-7471CRITICAL9.8Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a ...
CVE-2020-3927HIGH7.5An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific ...
CVE-2020-3926HIGH7.5An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific ...
CVE-2020-3925HIGH8.8A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long ...
CVE-2020-8508CRITICAL9.8nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of func...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now