2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-21992HIGH8.8Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. T...
CVE-2020-21990HIGH7.5Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vuln...
CVE-2020-36327HIGH8.8Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem ve...
CVE-2020-7038HIGH7.5A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an una...
CVE-2020-7037HIGH8.1An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an auth...
CVE-2020-22790MEDIUM5.4Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby inject...
CVE-2020-22789MEDIUM6.1Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileg...
CVE-2020-22785HIGH7.5Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting rando...
CVE-2020-22784HIGH7.5In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retriev...
CVE-2020-22783MEDIUM6.5Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database ...
CVE-2020-22782HIGH7.5Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import end...
CVE-2020-22781HIGH7.5In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denia...
CVE-2020-18022MEDIUM6.1Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtai...
CVE-2020-17999MEDIUM6.1Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via ...
CVE-2020-7123HIGH7.8A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5...
CVE-2020-21996HIGH7.5AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to ca...
CVE-2020-21994CRITICAL9.8AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated atta...
CVE-2020-21993MEDIUM6.1In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before bein...
CVE-2020-21991CRITICAL9.8AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly c...
CVE-2020-18020CRITICAL9.8SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands int...
CVE-2020-18019HIGH7.5SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary c...
CVE-2020-36326CRITICAL9.8PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname...
CVE-2020-22001CRITICAL9.8HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-For...
CVE-2020-22000HIGH8HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. ...
CVE-2020-21998MEDIUM6.1In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified befor...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now