2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35755HIGH7.5An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Inf...
CVE-2020-28945MEDIUM6.1OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://oner...
CVE-2020-20247MEDIUM6.5Mikrotik RouterOs before 6.46.5 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute...
CVE-2020-20218MEDIUM6.5Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute pro...
CVE-2020-28944HIGH7.5OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of d...
CVE-2020-28943MEDIUM6.5OX App Suite 7.10.4 and earlier allows SSRF via a snippet.
CVE-2020-18084MEDIUM6.1Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into t...
CVE-2020-7731HIGH7.5This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereferen...
CVE-2020-4039CRITICAL9.1SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversa...
CVE-2020-15153CRITICAL9.8Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Secur...
CVE-2020-27519HIGH7.8Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The at...
CVE-2020-24918CRITICAL9.8A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to...
CVE-2020-1721MEDIUM6.1A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitiz...
CVE-2020-18070CRITICAL9.1Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP reque...
CVE-2020-18035MEDIUM6.1Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into...
CVE-2020-15225MEDIUM6.5django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before versi...
CVE-2020-22808MEDIUM6.1An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page.
CVE-2020-22807CRITICAL9.8An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
CVE-2020-18032HIGH7.8Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to exe...
CVE-2020-35430CRITICAL9.8SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to ...
CVE-2020-21452CRITICAL9.8An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious cod...
CVE-2020-21101MEDIUM5.4Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite...
CVE-2020-22002HIGH7.5An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI...
CVE-2020-21997HIGH7.5Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vul...
CVE-2020-21995CRITICAL9.8Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to g...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now