2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-1693CRITICAL9.8A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api ...
CVE-2020-9006CRITICAL9.8The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups funct...
CVE-2020-8518CRITICAL9.8Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu...
CVE-2020-8427CRITICAL9.8In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that...
CVE-2020-5531CRITICAL9.8Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V,...
CVE-2020-9027CRITICAL9.8ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The N...
CVE-2020-9026CRITICAL9.8ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NT...
CVE-2020-9024CRITICAL9.8Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (e...
CVE-2020-9023CRITICAL9.8Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured wit...
CVE-2020-9021CRITICAL9.8Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12....
CVE-2020-9020CRITICAL9.8Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timecon...
CVE-2020-8129CRITICAL9.8An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execu...
CVE-2020-8128CRITICAL9.8An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attack...
CVE-2020-8612CRITICAL9In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately ...
CVE-2020-8803CRITICAL9.8SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospe...
CVE-2020-8802CRITICAL9.8SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
CVE-2020-8614CRITICAL9.8An issue was discovered on Askey AP4000W TDC_V1.01.003 devices. An attacker can perform Remote Code Execution (RCE) by s...
CVE-2020-3763CRITICAL9.8Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an...
CVE-2020-3762CRITICAL9.8Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an...
CVE-2020-3760CRITICAL9.8Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could l...
CVE-2020-3754CRITICAL9.8Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an...
CVE-2020-3752CRITICAL9.8Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an...
CVE-2020-3751CRITICAL9.8Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an...
CVE-2020-3750CRITICAL9.8Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an...
CVE-2020-3749CRITICAL9.8Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, an...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now