2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-6959CRITICAL9.8The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT...
CVE-2020-7229CRITICAL9.8An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search en...
CVE-2020-7233CRITICAL9.8KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Log...
CVE-2020-7048CRITICAL9.1The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any ...
CVE-2020-2587CRITICAL9.9Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Suppo...
CVE-2020-2586CRITICAL9.9Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Suppo...
CVE-2020-2555CRITICAL9.8Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su...
CVE-2020-2551CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor...
CVE-2020-2546CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - Java...
CVE-2020-0654CRITICAL9.1A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to byp...
CVE-2020-0646CRITICAL9.8A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N...
CVE-2020-0610CRITICAL9.8A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta...
CVE-2020-0609CRITICAL9.8A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta...
CVE-2020-5505CRITICAL9.8Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction...
CVE-2020-6958CRITICAL9.1An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other p...
CVE-2020-6948CRITICAL9.8A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a...
CVE-2020-6840CRITICAL9.8In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.
CVE-2020-6839CRITICAL9.8In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.
CVE-2020-6838CRITICAL9.8In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
CVE-2020-6836CRITICAL9.8grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injectio...
CVE-2020-6835CRITICAL9.8An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
CVE-2020-6162CRITICAL9.1An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitia...
CVE-2020-6756CRITICAL9.8languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re...
CVE-2020-5510CRITICAL9.8PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
CVE-2020-6170CRITICAL9.8An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now