2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21992 | HIGH | 8.8 | 5.2% | Apr 29, 2021 | Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. T... |
| CVE-2020-21990 | HIGH | 7.5 | 2.3% | Apr 29, 2021 | Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vuln... |
| CVE-2020-36327 | HIGH | 8.8 | 6.3% | Apr 29, 2021 | Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem ve... |
| CVE-2020-7038 | HIGH | 7.5 | 1.3% | Apr 28, 2021 | A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an una... |
| CVE-2020-7037 | HIGH | 8.1 | 1.1% | Apr 28, 2021 | An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an auth... |
| CVE-2020-22790 | MEDIUM | 5.4 | 1.3% | Apr 28, 2021 | Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby inject... |
| CVE-2020-22789 | MEDIUM | 6.1 | 1.2% | Apr 28, 2021 | Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileg... |
| CVE-2020-22785 | HIGH | 7.5 | 1.1% | Apr 28, 2021 | Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting rando... |
| CVE-2020-22784 | HIGH | 7.5 | 1.0% | Apr 28, 2021 | In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retriev... |
| CVE-2020-22783 | MEDIUM | 6.5 | 0.6% | Apr 28, 2021 | Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database ... |
| CVE-2020-22782 | HIGH | 7.5 | 1.1% | Apr 28, 2021 | Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import end... |
| CVE-2020-22781 | HIGH | 7.5 | 1.1% | Apr 28, 2021 | In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denia... |
| CVE-2020-18022 | MEDIUM | 6.1 | 1.2% | Apr 28, 2021 | Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtai... |
| CVE-2020-17999 | MEDIUM | 6.1 | 1.6% | Apr 28, 2021 | Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via ... |
| CVE-2020-7123 | HIGH | 7.8 | 0.2% | Apr 28, 2021 | A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5... |
| CVE-2020-21996 | HIGH | 7.5 | 3.6% | Apr 28, 2021 | AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to ca... |
| CVE-2020-21994 | CRITICAL | 9.8 | 3.7% | Apr 28, 2021 | AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated atta... |
| CVE-2020-21993 | MEDIUM | 6.1 | 0.8% | Apr 28, 2021 | In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before bein... |
| CVE-2020-21991 | CRITICAL | 9.8 | 2.9% | Apr 28, 2021 | AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly c... |
| CVE-2020-18020 | CRITICAL | 9.8 | 3.8% | Apr 28, 2021 | SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands int... |
| CVE-2020-18019 | HIGH | 7.5 | 1.5% | Apr 28, 2021 | SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary c... |
| CVE-2020-36326 | CRITICAL | 9.8 | 3.1% | Apr 28, 2021 | PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname... |
| CVE-2020-22001 | CRITICAL | 9.8 | 3.4% | Apr 27, 2021 | HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-For... |
| CVE-2020-22000 | HIGH | 8 | 1.1% | Apr 27, 2021 | HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. ... |
| CVE-2020-21998 | MEDIUM | 6.1 | 1.3% | Apr 27, 2021 | In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified befor... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now