2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-18684CRITICAL9.8Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port n...
CVE-2020-18683CRITICAL9.8Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined...
CVE-2020-12030CRITICAL10There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. ...
CVE-2020-20122CRITICAL9.8Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/conte...
CVE-2020-20120CRITICAL9.8ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the ...
CVE-2020-4690CRITICAL9.8IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i...
CVE-2020-26301CRITICAL10ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a comman...
CVE-2020-12083CRITICAL9.9An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 ...
CVE-2020-14124CRITICAL9.8There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router ...
CVE-2020-14119CRITICAL9.8There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under adminis...
CVE-2020-21322CRITICAL9.8An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a cr...
CVE-2020-21127CRITICAL9.8MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
CVE-2020-21125CRITICAL9.8An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.
CVE-2020-21124CRITICAL9.8UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
CVE-2020-21121CRITICAL9.8Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_m...
CVE-2020-19267CRITICAL9.8An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading ...
CVE-2020-7873CRITICAL9.8Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to...
CVE-2020-26300CRITICAL9.8systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation be...
CVE-2020-26772CRITICAL9.8Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.
CVE-2020-19138CRITICAL9.8Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary...
CVE-2020-24672CRITICAL9.8A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer runni...
CVE-2020-11264CRITICAL9.8Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packe...
CVE-2020-19853CRITICAL9.8BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
CVE-2020-19751CRITICAL9.1An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read...
CVE-2020-7865CRITICAL9.8A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now