2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25864MEDIUM6.1HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scriptin...
CVE-2020-14105MEDIUM5.5The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
CVE-2020-7856CRITICAL9.8A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exis...
CVE-2020-27241CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber par...
CVE-2020-27240CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus ...
CVE-2020-28141MEDIUM5.4The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated us...
CVE-2020-7851HIGH7.8Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could ...
CVE-2020-36195CRITICAL9.8An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming ad...
CVE-2020-2509CRITICAL9.8A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows...
CVE-2020-9681MEDIUM6.5Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut...
CVE-2020-9668HIGH7.8Adobe Genuine Service version 6.6 (and earlier) is affected by an Improper Access control vulnerability when handling sy...
CVE-2020-9667MEDIUM6.5Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut...
CVE-2020-28898MEDIUM5.3In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a ...
CVE-2020-28593HIGH8.1A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF...
CVE-2020-28592CRITICAL9.8A heap-based buffer overflow vulnerability exists in the configuration server functionality of the Cosori Smart 5.8-Quar...
CVE-2020-27239CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus para...
CVE-2020-27238CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter i...
CVE-2020-27237CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter i...
CVE-2020-7308MEDIUM6.5Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Febru...
CVE-2020-7270MEDIUM4.3Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re...
CVE-2020-7269MEDIUM4.3Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re...
CVE-2020-36288MEDIUM6.1The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before ver...
CVE-2020-35660MEDIUM5.4Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.
CVE-2020-28124MEDIUM5.4Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field.
CVE-2020-35419MEDIUM6.1Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now