2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-18684 | CRITICAL | 9.8 | 1.3% | Sep 30, 2021 | Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port n... |
| CVE-2020-18683 | CRITICAL | 9.8 | 1.3% | Sep 30, 2021 | Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined... |
| CVE-2020-12030 | CRITICAL | 10 | 1.1% | Sep 29, 2021 | There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. ... |
| CVE-2020-20122 | CRITICAL | 9.8 | 1.2% | Sep 28, 2021 | Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/conte... |
| CVE-2020-20120 | CRITICAL | 9.8 | 1.7% | Sep 28, 2021 | ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the ... |
| CVE-2020-4690 | CRITICAL | 9.8 | 1.1% | Sep 23, 2021 | IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i... |
| CVE-2020-26301 | CRITICAL | 10 | 3.8% | Sep 20, 2021 | ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a comman... |
| CVE-2020-12083 | CRITICAL | 9.9 | 0.9% | Sep 17, 2021 | An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 ... |
| CVE-2020-14124 | CRITICAL | 9.8 | 1.9% | Sep 16, 2021 | There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router ... |
| CVE-2020-14119 | CRITICAL | 9.8 | 3.0% | Sep 16, 2021 | There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under adminis... |
| CVE-2020-21322 | CRITICAL | 9.8 | 1.7% | Sep 15, 2021 | An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a cr... |
| CVE-2020-21127 | CRITICAL | 9.8 | 1.6% | Sep 15, 2021 | MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel. |
| CVE-2020-21125 | CRITICAL | 9.8 | 1.7% | Sep 15, 2021 | An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code. |
| CVE-2020-21124 | CRITICAL | 9.8 | 2.1% | Sep 15, 2021 | UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page. |
| CVE-2020-21121 | CRITICAL | 9.8 | 1.1% | Sep 15, 2021 | Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_m... |
| CVE-2020-19267 | CRITICAL | 9.8 | 1.6% | Sep 9, 2021 | An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading ... |
| CVE-2020-7873 | CRITICAL | 9.8 | 0.6% | Sep 9, 2021 | Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to... |
| CVE-2020-26300 | CRITICAL | 9.8 | 1.4% | Sep 9, 2021 | systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation be... |
| CVE-2020-26772 | CRITICAL | 9.8 | 4.0% | Sep 8, 2021 | Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function. |
| CVE-2020-19138 | CRITICAL | 9.8 | 5.6% | Sep 8, 2021 | Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary... |
| CVE-2020-24672 | CRITICAL | 9.8 | 0.5% | Sep 8, 2021 | A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer runni... |
| CVE-2020-11264 | CRITICAL | 9.8 | 13.2% | Sep 8, 2021 | Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packe... |
| CVE-2020-19853 | CRITICAL | 9.8 | 1.1% | Sep 8, 2021 | BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php. |
| CVE-2020-19751 | CRITICAL | 9.1 | 1.3% | Sep 7, 2021 | An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read... |
| CVE-2020-7865 | CRITICAL | 9.8 | 0.9% | Sep 7, 2021 | A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now