2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-8599CRITICAL9.8Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to...
CVE-2020-8598CRITICAL9.8Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl...
CVE-2020-10121CRITICAL9.8cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).
CVE-2020-10119CRITICAL9.8cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
CVE-2020-10118CRITICAL9.1cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).
CVE-2020-10117CRITICAL9.1cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).
CVE-2020-10380CRITICAL9.8RMySQL through 0.10.19 allows SQL Injection.
CVE-2020-9347CRITICAL9.8Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name tha...
CVE-2020-8786CRITICAL9.8SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
CVE-2020-8785CRITICAL9.8SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
CVE-2020-8784CRITICAL9.8SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
CVE-2020-8783CRITICAL9.8SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
CVE-2020-5847CRITICAL9.8Unraid through 6.8.0 allows Remote Code Execution.
CVE-2020-6990CRITICAL9.8Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Cont...
CVE-2020-10243CRITICAL9.8An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a S...
CVE-2020-10230CRITICAL9.8CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/adm...
CVE-2020-5547CRITICAL9.8Resource Management Errors vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 seri...
CVE-2020-5545CRITICAL9.8TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and ear...
CVE-2020-5544CRITICAL9.8Null Pointer Dereference vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series...
CVE-2020-5543CRITICAL9.8TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and ear...
CVE-2020-5542CRITICAL9.8Buffer error vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D ...
CVE-2020-7607CRITICAL9.8gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in ...
CVE-2020-7606CRITICAL9.8docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the fu...
CVE-2020-7605CRITICAL9.8gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of '...
CVE-2020-7604CRITICAL9.8pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be cont...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now