2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35755 | HIGH | 7.5 | 1.1% | May 3, 2021 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Inf... |
| CVE-2020-28945 | MEDIUM | 6.1 | 1.1% | May 3, 2021 | OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as  suffers from a memory corruption vulnerability in the /nova/bin/traceroute... |
| CVE-2020-20218 | MEDIUM | 6.5 | 2.0% | May 3, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute pro... |
| CVE-2020-28944 | HIGH | 7.5 | 1.6% | Apr 30, 2021 | OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of d... |
| CVE-2020-28943 | MEDIUM | 6.5 | 1.2% | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows SSRF via a snippet. |
| CVE-2020-18084 | MEDIUM | 6.1 | 1.3% | Apr 30, 2021 | Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into t... |
| CVE-2020-7731 | HIGH | 7.5 | 1.7% | Apr 30, 2021 | This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereferen... |
| CVE-2020-4039 | CRITICAL | 9.1 | 1.4% | Apr 30, 2021 | SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversa... |
| CVE-2020-15153 | CRITICAL | 9.8 | 2.4% | Apr 30, 2021 | Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Secur... |
| CVE-2020-27519 | HIGH | 7.8 | 0.3% | Apr 30, 2021 | Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The at... |
| CVE-2020-24918 | CRITICAL | 9.8 | 4.4% | Apr 30, 2021 | A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to... |
| CVE-2020-1721 | MEDIUM | 6.1 | 1.0% | Apr 30, 2021 | A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitiz... |
| CVE-2020-18070 | CRITICAL | 9.1 | 2.2% | Apr 30, 2021 | Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP reque... |
| CVE-2020-18035 | MEDIUM | 6.1 | 1.0% | Apr 29, 2021 | Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into... |
| CVE-2020-15225 | MEDIUM | 6.5 | 1.8% | Apr 29, 2021 | django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before versi... |
| CVE-2020-22808 | MEDIUM | 6.1 | 0.8% | Apr 29, 2021 | An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page. |
| CVE-2020-22807 | CRITICAL | 9.8 | 1.3% | Apr 29, 2021 | An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. |
| CVE-2020-18032 | HIGH | 7.8 | 2.6% | Apr 29, 2021 | Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to exe... |
| CVE-2020-35430 | CRITICAL | 9.8 | 1.1% | Apr 29, 2021 | SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to ... |
| CVE-2020-21452 | CRITICAL | 9.8 | 1.1% | Apr 29, 2021 | An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious cod... |
| CVE-2020-21101 | MEDIUM | 5.4 | 0.6% | Apr 29, 2021 | Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite... |
| CVE-2020-22002 | HIGH | 7.5 | 1.4% | Apr 29, 2021 | An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI... |
| CVE-2020-21997 | HIGH | 7.5 | 2.7% | Apr 29, 2021 | Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vul... |
| CVE-2020-21995 | CRITICAL | 9.8 | 2.0% | Apr 29, 2021 | Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to g... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now