2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7832 | CRITICAL | 9.8 | 0.9% | Sep 7, 2021 | A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download ... |
| CVE-2020-18048 | CRITICAL | 9.8 | 1.7% | Sep 2, 2021 | An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered i... |
| CVE-2020-20495 | CRITICAL | 9.1 | 1.5% | Sep 1, 2021 | bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter. |
| CVE-2020-22848 | CRITICAL | 9.8 | 2.9% | Aug 30, 2021 | A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arb... |
| CVE-2020-15744 | CRITICAL | 9.8 | 1.4% | Aug 30, 2021 | Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker... |
| CVE-2020-18114 | CRITICAL | 9.8 | 1.9% | Aug 27, 2021 | An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a we... |
| CVE-2020-18106 | CRITICAL | 9.8 | 1.0% | Aug 27, 2021 | The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection. |
| CVE-2020-19001 | CRITICAL | 9.8 | 4.3% | Aug 27, 2021 | Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 ... |
| CVE-2020-20675 | CRITICAL | 9.8 | 1.1% | Aug 26, 2021 | Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/. |
| CVE-2020-19705 | CRITICAL | 9.8 | 1.0% | Aug 26, 2021 | thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add. |
| CVE-2020-25359 | CRITICAL | 9.1 | 2.3% | Aug 20, 2021 | An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers th... |
| CVE-2020-36474 | CRITICAL | 9.8 | 1.8% | Aug 20, 2021 | SafeCurl before 0.9.2 has a DNS rebinding vulnerability. |
| CVE-2020-18879 | CRITICAL | 9.8 | 3.1% | Aug 20, 2021 | Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files... |
| CVE-2020-35685 | CRITICAL | 9.1 | 2.1% | Aug 19, 2021 | An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connectio... |
| CVE-2020-25928 | CRITICAL | 9.8 | 3.6% | Aug 18, 2021 | The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary ... |
| CVE-2020-18164 | CRITICAL | 9.8 | 1.1% | Aug 17, 2021 | SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter. |
| CVE-2020-22937 | CRITICAL | 9.8 | 2.8% | Aug 17, 2021 | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via... |
| CVE-2020-18705 | CRITICAL | 9.8 | 2.8% | Aug 16, 2021 | XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka... |
| CVE-2020-18704 | CRITICAL | 9.8 | 2.9% | Aug 16, 2021 | Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code... |
| CVE-2020-18703 | CRITICAL | 9.8 | 2.8% | Aug 16, 2021 | XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka... |
| CVE-2020-18701 | CRITICAL | 9.8 | 2.3% | Aug 16, 2021 | Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain pri... |
| CVE-2020-18698 | CRITICAL | 9.8 | 2.0% | Aug 16, 2021 | Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without res... |
| CVE-2020-18758 | CRITICAL | 9.8 | 2.7% | Aug 13, 2021 | An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code. |
| CVE-2020-18753 | CRITICAL | 9.8 | 1.5% | Aug 13, 2021 | An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalat... |
| CVE-2020-36363 | CRITICAL | 9.8 | 0.7% | Aug 12, 2021 | Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now