2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4879 | CRITICAL | 9.8 | 1.5% | Jan 21, 2022 | IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused b... |
| CVE-2020-4877 | CRITICAL | 9.8 | 0.9% | Jan 21, 2022 | IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public field... |
| CVE-2020-28103 | CRITICAL | 9.8 | 1.1% | Jan 11, 2022 | cscms v4.1 allows for SQL injection via the "page_del" function. |
| CVE-2020-28102 | CRITICAL | 9.8 | 1.2% | Jan 11, 2022 | cscms v4.1 allows for SQL injection via the "js_del" function. |
| CVE-2020-7883 | CRITICAL | 9.8 | 0.9% | Dec 28, 2021 | Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download an... |
| CVE-2020-7878 | CRITICAL | 9.8 | 0.7% | Dec 28, 2021 | An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-... |
| CVE-2020-22057 | CRITICAL | 9.1 | 1.1% | Dec 28, 2021 | The WinRin0x64.sys and WinRing0.sys low-level drivers in EVGA Precision XOC version v6.2.7 were discovered to be configu... |
| CVE-2020-21238 | CRITICAL | 9.8 | 0.9% | Dec 27, 2021 | An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks. |
| CVE-2020-21237 | CRITICAL | 9.8 | 1.1% | Dec 27, 2021 | An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks. |
| CVE-2020-20944 | CRITICAL | 9.1 | 2.0% | Dec 27, 2021 | An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files. |
| CVE-2020-36514 | CRITICAL | 9.8 | 1.2% | Dec 27, 2021 | An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory... |
| CVE-2020-36513 | CRITICAL | 9.8 | 1.2% | Dec 27, 2021 | An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memo... |
| CVE-2020-36512 | CRITICAL | 9.8 | 1.2% | Dec 27, 2021 | An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitia... |
| CVE-2020-20601 | CRITICAL | 9.8 | 7.6% | Dec 22, 2021 | An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet. |
| CVE-2020-18078 | CRITICAL | 9.8 | 1.0% | Dec 17, 2021 | A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password. |
| CVE-2020-27416 | CRITICAL | 9.8 | 1.6% | Dec 8, 2021 | Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows r... |
| CVE-2020-29177 | CRITICAL | 9.1 | 0.9% | Dec 2, 2021 | Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php. |
| CVE-2020-7879 | CRITICAL | 9.8 | 1.4% | Nov 30, 2021 | This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extrac... |
| CVE-2020-7882 | CRITICAL | 9.1 | 1.2% | Nov 22, 2021 | Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and d... |
| CVE-2020-16152 | CRITICAL | 9.8 | 35.0% | Nov 14, 2021 | The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0... |
| CVE-2020-23878 | CRITICAL | 9.8 | 1.7% | Nov 10, 2021 | pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch. |
| CVE-2020-23877 | CRITICAL | 9.8 | 1.7% | Nov 10, 2021 | pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream. |
| CVE-2020-23874 | CRITICAL | 9.8 | 2.1% | Nov 10, 2021 | pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode. |
| CVE-2020-23873 | CRITICAL | 9.8 | 2.1% | Nov 10, 2021 | pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump. |
| CVE-2020-22226 | CRITICAL | 9.8 | 1.1% | Nov 5, 2021 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionS... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now