2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-18172CRITICAL9.8A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate pr...
CVE-2020-18170CRITICAL9.8An issue in the SeChangeNotifyPrivilege component of Abloy Key Manager Version 7.14301.0.0 allows attackers to escalate ...
CVE-2020-17952CRITICAL9.8A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbit...
CVE-2020-20741CRITICAL9.8Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_T...
CVE-2020-14032CRITICAL9.8ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.
CVE-2020-7388CRITICAL9.8Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side au...
CVE-2020-36033CRITICAL9.8SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php.
CVE-2020-21937CRITICAL9.8An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.9736...
CVE-2020-21935CRITICAL9.8A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 R...
CVE-2020-35427CRITICAL9.8SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbit...
CVE-2020-7866CRITICAL9.8When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper...
CVE-2020-5349CRITICAL9.8Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential v...
CVE-2020-5322CRITICAL9.1Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A re...
CVE-2020-4821CRITICAL9.8IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configuration...
CVE-2020-11633CRITICAL9.8The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfi...
CVE-2020-24133CRITICAL9.8A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows att...
CVE-2020-18155CRITICAL9.8SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
CVE-2020-18144CRITICAL9.8SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.
CVE-2020-22884CRITICAL9.8Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to ...
CVE-2020-22875CRITICAL9.8Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute ar...
CVE-2020-22874CRITICAL9.8Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute a...
CVE-2020-22873CRITICAL9.8Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute...
CVE-2020-11307CRITICAL9.8Buffer overflow in modem due to improper array index check before copying into it in Snapdragon Auto, Snapdragon Compute...
CVE-2020-18544CRITICAL9.8SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the componen...
CVE-2020-19038CRITICAL9.1File Deletion vulnerability in Halo 0.4.3 via delBackup.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now