2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-20979CRITICAL9.8An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute ar...
CVE-2020-20975CRITICAL9.8In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
CVE-2020-28165CRITICAL9.8The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload a...
CVE-2020-25566CRITICAL9.8In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in PO...
CVE-2020-25565CRITICAL9.8In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and ga...
CVE-2020-25563CRITICAL9.8In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by dire...
CVE-2020-25560CRITICAL9.8In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and ga...
CVE-2020-21359CRITICAL9.8An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix wh...
CVE-2020-23151CRITICAL9.8rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since t...
CVE-2020-36452CRITICAL9.8An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of un...
CVE-2020-36443CRITICAL9.8An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRe...
CVE-2020-36434CRITICAL9.8An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free...
CVE-2020-36432CRITICAL9.8An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matr...
CVE-2020-28088CRITICAL9.8An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execut...
CVE-2020-19305CRITICAL9.8An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when ...
CVE-2020-19302CRITICAL9.8An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a websh...
CVE-2020-19301CRITICAL9.8A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a...
CVE-2020-21809CRITICAL9.8SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and t...
CVE-2020-21808CRITICAL9.8SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics...
CVE-2020-21806CRITICAL9.8SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..
CVE-2020-18175CRITICAL9.8SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.
CVE-2020-18013CRITICAL9.8SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm.
CVE-2020-36239CRITICAL9.8Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8...
CVE-2020-5341CRITICAL9.8Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2...
CVE-2020-18174CRITICAL9.8A process injection vulnerability in setup.exe of AutoHotkey 1.1.32.00 allows attackers to escalate privileges.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now