2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-9370CRITICAL9.1HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
CVE-2020-10106CRITICAL9.8PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in in...
CVE-2020-9054CRITICAL9.8Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command...
CVE-2020-9550CRITICAL9.8Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attack...
CVE-2020-9477CRITICAL9.8An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in...
CVE-2020-9761CRITICAL9.8An issue was discovered in UNCTAD ASYCUDA World 2001 through 2020. The Java RMI Server has an Insecure Default Configura...
CVE-2020-9757CRITICAL9.8The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed ...
CVE-2020-9751CRITICAL9.1Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and exec...
CVE-2020-10018CRITICAL9.8WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory co...
CVE-2020-1731CRITICAL9.8A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator gene...
CVE-2020-9548CRITICAL9.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9547CRITICAL9.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9546CRITICAL9.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9465CRITICAL9.8An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL...
CVE-2020-8132CRITICAL9.8Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF fi...
CVE-2020-9434CRITICAL9.1openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean...
CVE-2020-9433CRITICAL9.1openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean ...
CVE-2020-9432CRITICAL9.1openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean f...
CVE-2020-7061CRITICAL9.1In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, c...
CVE-2020-7043CRITICAL9.1An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate vali...
CVE-2020-3924CRITICAL9.8DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers c...
CVE-2020-3923CRITICAL9.8DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism...
CVE-2020-9406CRITICAL9.8IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
CVE-2020-9398CRITICAL9.8ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQ...
CVE-2020-8794CRITICAL9.8OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now