2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7799HIGH7.2An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Se...
CVE-2020-5523HIGH7.4Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificat...
CVE-2020-7998HIGH8.8An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerabili...
CVE-2020-7997MEDIUM6.1ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.
CVE-2020-1933MEDIUM6.1A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through acti...
CVE-2020-1932MEDIUM6.5An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Su...
CVE-2020-1928MEDIUM5.3An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed...
CVE-2020-0549MEDIUM5.5Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially ...
CVE-2020-0548MEDIUM5.5Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure ...
CVE-2020-8091MEDIUM6.1svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cr...
CVE-2020-8090MEDIUM4.8The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a succes...
CVE-2020-5220MEDIUM5.3Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data ...
CVE-2020-5218MEDIUM4.3Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in product...
CVE-2020-8088CRITICAL9.8panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password has...
CVE-2020-8087CRITICAL9.8SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network D...
CVE-2020-5207HIGH7.5In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and T...
CVE-2020-7952HIGH7.8rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service ...
CVE-2020-7951HIGH7.8meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by cr...
CVE-2020-7950HIGH7.8meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by cr...
CVE-2020-7949HIGH7.8schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by ...
CVE-2020-7238HIGH7.5Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Tr...
CVE-2020-8009HIGH7.5AVB MOTU devices through 2020-01-22 allow /.. Directory Traversal, as demonstrated by reading the /etc/passwd file.
CVE-2020-5522HIGH7.4The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-...
CVE-2020-5521HIGH7.4The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-t...
CVE-2020-5520HIGH7.4The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-midd...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now