2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4926 | CRITICAL | 9.1 | 0.6% | May 24, 2022 | A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized acc... |
| CVE-2020-16209 | CRITICAL | 9.8 | 1.4% | May 19, 2022 | A malicious attacker could exploit the interface of the Fieldcomm Group HART-IP (release 1.0.0.0) by constructing messag... |
| CVE-2020-14496 | CRITICAL | 9.8 | 0.8% | May 19, 2022 | Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software P... |
| CVE-2020-19213 | CRITICAL | 9.8 | 15.8% | May 6, 2022 | SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. |
| CVE-2020-23621 | CRITICAL | 9.8 | 1.9% | May 2, 2022 | The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerabili... |
| CVE-2020-23620 | CRITICAL | 9.8 | 1.9% | May 2, 2022 | The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to i... |
| CVE-2020-13567 | CRITICAL | 9.8 | 2.3% | Apr 18, 2022 | Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL inject... |
| CVE-2020-22253 | CRITICAL | 9.8 | 1.1% | Apr 6, 2022 | Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2... |
| CVE-2020-19229 | CRITICAL | 9.8 | 1.4% | Apr 5, 2022 | Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deseria... |
| CVE-2020-24770 | CRITICAL | 9.8 | 2.4% | Mar 30, 2022 | SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2020-24769 | CRITICAL | 9.8 | 1.9% | Mar 30, 2022 | SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands... |
| CVE-2020-25176 | CRITICAL | 9.8 | 6.1% | Mar 18, 2022 | Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform... |
| CVE-2020-16232 | CRITICAL | 9.8 | 0.7% | Mar 18, 2022 | In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project ... |
| CVE-2020-15591 | CRITICAL | 9.8 | 3.8% | Mar 17, 2022 | fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote c... |
| CVE-2020-14115 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio... |
| CVE-2020-12775 | CRITICAL | 9.8 | 2.9% | Mar 1, 2022 | Hicos citizen certificate client-side component does not filter special characters for command parameters in specific we... |
| CVE-2020-10640 | CRITICAL | 9.8 | 3.0% | Feb 24, 2022 | Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges ... |
| CVE-2020-26728 | CRITICAL | 9.8 | 3.5% | Feb 11, 2022 | A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allow... |
| CVE-2020-14523 | CRITICAL | 9.8 | 2.2% | Feb 11, 2022 | Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitra... |
| CVE-2020-14521 | CRITICAL | 9.8 | 1.2% | Feb 11, 2022 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerabil... |
| CVE-2020-36062 | CRITICAL | 9.8 | 2.3% | Feb 11, 2022 | Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows a... |
| CVE-2020-13675 | CRITICAL | 9.8 | 1.2% | Feb 11, 2022 | Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all... |
| CVE-2020-36064 | CRITICAL | 9.8 | 1.5% | Jan 31, 2022 | Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attacker... |
| CVE-2020-25905 | CRITICAL | 9.8 | 1.7% | Jan 28, 2022 | An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1... |
| CVE-2020-17383 | CRITICAL | 9.8 | 4.3% | Jan 24, 2022 | A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root l... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now