2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-4879CRITICAL9.8IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused b...
CVE-2020-4877CRITICAL9.8IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public field...
CVE-2020-28103CRITICAL9.8cscms v4.1 allows for SQL injection via the "page_del" function.
CVE-2020-28102CRITICAL9.8cscms v4.1 allows for SQL injection via the "js_del" function.
CVE-2020-7883CRITICAL9.8Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download an...
CVE-2020-7878CRITICAL9.8An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-...
CVE-2020-22057CRITICAL9.1The WinRin0x64.sys and WinRing0.sys low-level drivers in EVGA Precision XOC version v6.2.7 were discovered to be configu...
CVE-2020-21238CRITICAL9.8An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
CVE-2020-21237CRITICAL9.8An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
CVE-2020-20944CRITICAL9.1An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
CVE-2020-36514CRITICAL9.8An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory...
CVE-2020-36513CRITICAL9.8An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memo...
CVE-2020-36512CRITICAL9.8An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitia...
CVE-2020-20601CRITICAL9.8An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
CVE-2020-18078CRITICAL9.8A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
CVE-2020-27416CRITICAL9.8Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows r...
CVE-2020-29177CRITICAL9.1Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php.
CVE-2020-7879CRITICAL9.8This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extrac...
CVE-2020-7882CRITICAL9.1Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and d...
CVE-2020-16152CRITICAL9.8The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0...
CVE-2020-23878CRITICAL9.8pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.
CVE-2020-23877CRITICAL9.8pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.
CVE-2020-23874CRITICAL9.8pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode.
CVE-2020-23873CRITICAL9.8pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump.
CVE-2020-22226CRITICAL9.8Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionS...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now