2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6617HIGH8.8stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
CVE-2020-6615MEDIUM6.5GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated...
CVE-2020-6614HIGH8.1GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
CVE-2020-6613HIGH8.1GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
CVE-2020-6612HIGH8.1GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
CVE-2020-6611MEDIUM6.5GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
CVE-2020-6610MEDIUM6.5GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
CVE-2020-6609HIGH8.8GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
CVE-2020-6583MEDIUM6.1BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can e...
CVE-2020-0008MEDIUM4.7In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race con...
CVE-2020-0007MEDIUM5.5In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. Th...
CVE-2020-0006MEDIUM6.5In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uni...
CVE-2020-0004MEDIUM5.5In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture ...
CVE-2020-0003MEDIUM6.7In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulne...
CVE-2020-0002HIGH8.8In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead...
CVE-2020-0001HIGH7.8In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to loc...
CVE-2020-5511HIGH8.8PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administ...
CVE-2020-5510CRITICAL9.8PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
CVE-2020-5183HIGH7.5FTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string ...
CVE-2020-0009MEDIUM5.5In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This...
CVE-2020-6170CRITICAL9.8An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl...
CVE-2020-6163MEDIUM6.1The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySug...
CVE-2020-5841CRITICAL9.8An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL inj...
CVE-2020-5842MEDIUM6.1Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. ...
CVE-2020-5307CRITICAL9.8PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username paramet...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now