2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6954MEDIUM6.5An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Conne...
CVE-2020-6832MEDIUM5.3An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was...
CVE-2020-5197MEDIUM4.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrec...
CVE-2020-6949HIGH8.8A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can ...
CVE-2020-6948CRITICAL9.8A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a...
CVE-2020-5390HIGH7.5PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is ef...
CVE-2020-5195MEDIUM6.1Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacke...
CVE-2020-6859MEDIUM5.3Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin...
CVE-2020-6860HIGH8.8libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header mess...
CVE-2020-6851HIGH7.5OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack ...
CVE-2020-6848MEDIUM6.1Axper Vision II 4 devices allow XSS via the DEVICE_NAME (aka Device Name) parameter to the configWebParams.cgi URI.
CVE-2020-6847MEDIUM5.4OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a me...
CVE-2020-6840CRITICAL9.8In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.
CVE-2020-6839CRITICAL9.8In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.
CVE-2020-6838CRITICAL9.8In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
CVE-2020-6836CRITICAL9.8grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injectio...
CVE-2020-6377HIGH8.8Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap co...
CVE-2020-6835CRITICAL9.8An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
CVE-2020-6162CRITICAL9.1An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitia...
CVE-2020-1767MEDIUM4.3Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely a...
CVE-2020-1766MEDIUM6.1Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents brow...
CVE-2020-1765MEDIUM5.3An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, A...
CVE-2020-6758MEDIUM6.1A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI...
CVE-2020-6757HIGH8.8contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers t...
CVE-2020-6756CRITICAL9.8languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now