2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5504 | HIGH | 8.8 | 38.8% | Jan 9, 2020 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could ... |
| CVE-2020-6750 | MEDIUM | 5.9 | 2.2% | Jan 9, 2020 | GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting v... |
| CVE-2020-6168 | HIGH | 7.6 | 2.0% | Jan 9, 2020 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with bas... |
| CVE-2020-6166 | MEDIUM | 5.4 | 1.1% | Jan 9, 2020 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with bas... |
| CVE-2020-6167 | HIGH | 8.8 | 0.9% | Jan 9, 2020 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable main... |
| CVE-2020-1925 | HIGH | 7.5 | 2.8% | Jan 9, 2020 | Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location head... |
| CVE-2020-1810 | MEDIUM | 5.3 | 0.5% | Jan 9, 2020 | There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL ... |
| CVE-2020-1786 | MEDIUM | 4.6 | 0.2% | Jan 9, 2020 | HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerabilit... |
| CVE-2020-1826 | MEDIUM | 4.4 | 0.1% | Jan 9, 2020 | Huawei Honor Magic2 mobile phones with versions earlier than 10.0.0.175(C00E59R2P11) have an information leak vulnerabil... |
| CVE-2020-1787 | MEDIUM | 6.6 | 0.3% | Jan 9, 2020 | HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. T... |
| CVE-2020-5308 | MEDIUM | 6.1 | 1.3% | Jan 9, 2020 | PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode ... |
| CVE-2020-6632 | MEDIUM | 6.1 | 0.7% | Jan 9, 2020 | In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAcce... |
| CVE-2020-6631 | MEDIUM | 5.5 | 0.8% | Jan 9, 2020 | An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_proces... |
| CVE-2020-6630 | MEDIUM | 5.5 | 0.8% | Jan 9, 2020 | An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_dat... |
| CVE-2020-6629 | MEDIUM | 6.5 | 1.3% | Jan 9, 2020 | Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c. |
| CVE-2020-6628 | HIGH | 8.8 | 1.5% | Jan 9, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c. |
| CVE-2020-5205 | MEDIUM | 5.4 | 0.8% | Jan 9, 2020 | In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attac... |
| CVE-2020-6625 | HIGH | 7.1 | 1.4% | Jan 9, 2020 | jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c. |
| CVE-2020-6624 | HIGH | 7.1 | 1.4% | Jan 9, 2020 | jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c. |
| CVE-2020-6623 | HIGH | 8.8 | 1.5% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index. |
| CVE-2020-6622 | HIGH | 8.8 | 1.4% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8. |
| CVE-2020-6621 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT. |
| CVE-2020-6620 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8. |
| CVE-2020-6619 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek. |
| CVE-2020-6618 | HIGH | 8.8 | 1.1% | Jan 8, 2020 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now