2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35494 | MEDIUM | 6.1 | 1.1% | Jan 4, 2021 | There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed ... |
| CVE-2020-35493 | MEDIUM | 5.5 | 1.1% | Jan 4, 2021 | A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump cou... |
| CVE-2020-4928 | MEDIUM | 6.7 | 0.4% | Jan 4, 2021 | IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request ... |
| CVE-2020-4918 | MEDIUM | 4.4 | 0.3% | Jan 4, 2021 | IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct... |
| CVE-2020-4916 | MEDIUM | 4.8 | 0.7% | Jan 4, 2021 | IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS... |
| CVE-2020-4913 | MEDIUM | 4.4 | 0.3% | Jan 4, 2021 | IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Forc... |
| CVE-2020-4910 | MEDIUM | 4.8 | 0.5% | Jan 4, 2021 | IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS... |
| CVE-2020-4909 | MEDIUM | 4.8 | 0.5% | Jan 4, 2021 | IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS... |
| CVE-2020-35964 | MEDIUM | 6.5 | 1.5% | Jan 3, 2021 | track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing. |
| CVE-2020-28841 | MEDIUM | 5.5 | 0.8% | Jan 3, 2021 | MyDrivers64.sys in DriverGenius 9.61.3708.3054 allows attackers to cause a system crash via the ioctl command 0x9c402000... |
| CVE-2020-35952 | MEDIUM | 6.5 | 0.9% | Jan 3, 2021 | login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish betwee... |
| CVE-2020-35391 | MEDIUM | 6.5 | 35.0% | Jan 1, 2021 | Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas... |
| CVE-2020-35946 | MEDIUM | 5.4 | 0.8% | Jan 1, 2021 | An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fiel... |
| CVE-2020-35934 | MEDIUM | 4.3 | 1.1% | Jan 1, 2021 | The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadat... |
| CVE-2020-35933 | MEDIUM | 6.5 | 0.9% | Jan 1, 2021 | A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress a... |
| CVE-2020-35930 | MEDIUM | 5.4 | 0.5% | Dec 31, 2020 | Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/we... |
| CVE-2020-25799 | MEDIUM | 5.4 | 0.7% | Dec 31, 2020 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey q... |
| CVE-2020-25797 | MEDIUM | 5.4 | 0.7% | Dec 31, 2020 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parame... |
| CVE-2020-11835 | MEDIUM | 5.5 | 0.3% | Dec 31, 2020 | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the... |
| CVE-2020-11834 | MEDIUM | 5.5 | 0.3% | Dec 31, 2020 | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fast... |
| CVE-2020-11833 | MEDIUM | 5.5 | 0.3% | Dec 31, 2020 | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2... |
| CVE-2020-11832 | MEDIUM | 5.5 | 0.3% | Dec 31, 2020 | In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/... |
| CVE-2020-35897 | MEDIUM | 4.7 | 0.2% | Dec 31, 2020 | An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread dat... |
| CVE-2020-35886 | MEDIUM | 4.7 | 0.2% | Dec 31, 2020 | An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across... |
| CVE-2020-35884 | MEDIUM | 6.5 | 1.1% | Dec 31, 2020 | An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malfo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now