2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-3716CRITICAL9.8Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserializa...
CVE-2020-7247CRITICAL9.8smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to ...
CVE-2020-5211CRITICAL9.8In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a...
CVE-2020-4207CRITICAL9.8IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by impr...
CVE-2020-5214CRITICAL9.8In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash...
CVE-2020-5213CRITICAL9.8In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow result...
CVE-2020-5212CRITICAL9.8In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow...
CVE-2020-8086CRITICAL9.8The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP addre...
CVE-2020-8088CRITICAL9.8panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password has...
CVE-2020-8087CRITICAL9.8SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network D...
CVE-2020-8001CRITICAL9.8The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.
CVE-2020-8000CRITICAL9.8Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.
CVE-2020-7999CRITICAL9.8The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.
CVE-2020-7995CRITICAL9.8The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attem...
CVE-2020-7981CRITICAL9.8sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with ...
CVE-2020-7980CRITICAL9.8Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th...
CVE-2020-6966CRITICAL10In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center...
CVE-2020-6965CRITICAL9.9In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center...
CVE-2020-6963CRITICAL10In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center...
CVE-2020-6962CRITICAL10In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente...
CVE-2020-6961CRITICAL10In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente...
CVE-2020-7245CRITICAL9.8Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arb...
CVE-2020-7941CRITICAL9.8A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some c...
CVE-2020-7109CRITICAL9.8The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
CVE-2020-6960CRITICAL9.8The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now