2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9060MEDIUM6.5Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 ve...
CVE-2020-9059MEDIUM6.5Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resourc...
CVE-2020-9058HIGH8.1Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to...
CVE-2020-9057HIGH8.8Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker w...
CVE-2020-29050HIGH7.5SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511)...
CVE-2020-10137MEDIUM6.5Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN...
CVE-2020-27428MEDIUM6.1A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrar...
CVE-2020-23986MEDIUM6.1Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site sc...
CVE-2020-5956HIGH7.5An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 bef...
CVE-2020-15933MEDIUM5.3A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail v...
CVE-2020-23026HIGH7.5A NULL pointer dereference in the main() function dhry_1.c of dhrystone 2.1 causes a denial of service (DoS).
CVE-2020-11263HIGH8.2An integer overflow due to improper check performed after the address and size passed are aligned in Snapdragon Compute,...
CVE-2020-29292MEDIUM6.5iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or ...
CVE-2020-7883CRITICAL9.8Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download an...
CVE-2020-7878CRITICAL9.8An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-...
CVE-2020-22061HIGH7.8SUPERAntispyware v8.0.0.1050 was discovered to contain an issue in the component saskutil64.sys. This issue allows attac...
CVE-2020-22057CRITICAL9.1The WinRin0x64.sys and WinRing0.sys low-level drivers in EVGA Precision XOC version v6.2.7 were discovered to be configu...
CVE-2020-21238CRITICAL9.8An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
CVE-2020-21237CRITICAL9.8An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
CVE-2020-21236HIGH8.8A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impers...
CVE-2020-20948HIGH7.5An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of th...
CVE-2020-20946MEDIUM5.4Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&...
CVE-2020-20945HIGH8.8A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to ...
CVE-2020-20944CRITICAL9.1An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
CVE-2020-20943MEDIUM4.3A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force v...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now