2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-13539HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V...
CVE-2020-4762HIGH8.8IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow...
CVE-2020-35488HIGH7.5The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of...
CVE-2020-17519HIGH7.5A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file...
CVE-2020-17518HIGH7.5Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the l...
CVE-2020-5361HIGH7.6Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist...
CVE-2020-29491HIGH8.6Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate...
CVE-2020-36156HIGH8.8An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalatio...
CVE-2020-36154HIGH7.8The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMD...
CVE-2020-25275HIGH7.5Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafte...
CVE-2020-22550HIGH7.5Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to do...
CVE-2020-4942HIGH8.8IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an at...
CVE-2020-4917HIGH8.8IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious ...
CVE-2020-4912HIGH7.2IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when ...
CVE-2020-35965HIGH7.5decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to...
CVE-2020-35963HIGH7.8flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correc...
CVE-2020-35962HIGH7.5The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum ...
CVE-2020-28852HIGH7.5In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processi...
CVE-2020-28851HIGH7.5In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- exten...
CVE-2020-35950HIGH8.8An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almos...
CVE-2020-35948HIGH8.8An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta...
CVE-2020-35947HIGH7.4An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lack...
CVE-2020-35945HIGH8.8An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authent...
CVE-2020-35944HIGH8.8An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vuln...
CVE-2020-35939HIGH8.8PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now