2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-28366HIGH7.5Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time ...
CVE-2020-28362HIGH7.5Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
CVE-2020-28091HIGH7.5cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame...
CVE-2020-25406HIGH7.3app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.
CVE-2020-24297HIGH8.8httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS com...
CVE-2020-7564HIGH8.8A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server...
CVE-2020-7563HIGH8.8A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premi...
CVE-2020-7562HIGH8.1A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premiu...
CVE-2020-28914HIGH7.1An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath vol...
CVE-2020-26552HIGH7.5An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints...
CVE-2020-26551HIGH7.5An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.
CVE-2020-26550HIGH7.5An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated s...
CVE-2020-26549HIGH7.5An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests t...
CVE-2020-26548HIGH8.8An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can ...
CVE-2020-28136HIGH8.8An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote...
CVE-2020-26405HIGH7.1Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to sa...
CVE-2020-25400HIGH7.5Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to acce...
CVE-2020-13958HIGH7.8A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks po...
CVE-2020-27554HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists whi...
CVE-2020-27553HIGH7.5In BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoo...
CVE-2020-21665HIGH7.2In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be pas...
CVE-2020-7841HIGH8.8Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution whe...
CVE-2020-28688HIGH8.8The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo...
CVE-2020-28687HIGH8.8The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upl...
CVE-2020-27192HIGH7.8BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now