2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-36880HIGH7.8Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that ...
CVE-2020-36879HIGH8.5Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabl...
CVE-2020-36878HIGH8.7ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed throug...
CVE-2020-36877CRITICAL9.3ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows a...
CVE-2020-36876HIGH8.7ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0....
CVE-2020-36874HIGH8.7ACE SECURITY WIP-90113 HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/...
CVE-2020-36873HIGH8.7Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthenticated configuration disclosure vulnera...
CVE-2020-36872HIGH8.7BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP ...
CVE-2020-36871HIGH8.7ESCAM QD-900 WIFI HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi351...
CVE-2020-36870CRITICAL9.2Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerabi...
CVE-2020-36869HIGH7.2Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitati...
CVE-2020-36868HIGH7.8Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The s...
CVE-2020-36867HIGH8.8Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functional...
CVE-2020-36866MEDIUM5.4Nagios XI versions prior to 5.7.3 are vulnerable to cross-site scripting (XSS) via the Manage Users page of the Admin in...
CVE-2020-36865MEDIUM5.4Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligenc...
CVE-2020-36864MEDIUM5.4Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dash...
CVE-2020-36863HIGH8.8Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that lo...
CVE-2020-36862MEDIUM6.1Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Craft...
CVE-2020-36861MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.8 / Nagios XI 5.7.5 contains multiple cross-site sc...
CVE-2020-36860MEDIUM5.4The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple cross-site sc...
CVE-2020-36859HIGH8.8The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection...
CVE-2020-36858MEDIUM5.4Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on th...
CVE-2020-36857HIGH7.2Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface ...
CVE-2020-36856HIGH8.8Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_te...
CVE-2020-36855MEDIUM5.5A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now