2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-7832CRITICAL9.8A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download ...
CVE-2020-18048CRITICAL9.8An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered i...
CVE-2020-20495CRITICAL9.1bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
CVE-2020-22848CRITICAL9.8A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arb...
CVE-2020-15744CRITICAL9.8Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker...
CVE-2020-18114CRITICAL9.8An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a we...
CVE-2020-18106CRITICAL9.8The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
CVE-2020-19001CRITICAL9.8Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 ...
CVE-2020-20675CRITICAL9.8Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/.
CVE-2020-19705CRITICAL9.8thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
CVE-2020-25359CRITICAL9.1An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers th...
CVE-2020-36474CRITICAL9.8SafeCurl before 0.9.2 has a DNS rebinding vulnerability.
CVE-2020-18879CRITICAL9.8Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files...
CVE-2020-35685CRITICAL9.1An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connectio...
CVE-2020-25928CRITICAL9.8The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary ...
CVE-2020-18164CRITICAL9.8SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
CVE-2020-22937CRITICAL9.8A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via...
CVE-2020-18705CRITICAL9.8XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka...
CVE-2020-18704CRITICAL9.8Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code...
CVE-2020-18703CRITICAL9.8XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka...
CVE-2020-18701CRITICAL9.8Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain pri...
CVE-2020-18698CRITICAL9.8Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without res...
CVE-2020-18758CRITICAL9.8An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
CVE-2020-18753CRITICAL9.8An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalat...
CVE-2020-36363CRITICAL9.8Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now