2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-18172 | CRITICAL | 9.8 | 1.3% | Jul 26, 2021 | A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate pr... |
| CVE-2020-18170 | CRITICAL | 9.8 | 1.3% | Jul 26, 2021 | An issue in the SeChangeNotifyPrivilege component of Abloy Key Manager Version 7.14301.0.0 allows attackers to escalate ... |
| CVE-2020-17952 | CRITICAL | 9.8 | 2.5% | Jul 26, 2021 | A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbit... |
| CVE-2020-20741 | CRITICAL | 9.8 | 1.6% | Jul 23, 2021 | Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_T... |
| CVE-2020-14032 | CRITICAL | 9.8 | 2.1% | Jul 23, 2021 | ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM. |
| CVE-2020-7388 | CRITICAL | 9.8 | 70.3% | Jul 22, 2021 | Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side au... |
| CVE-2020-36033 | CRITICAL | 9.8 | 1.1% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php. |
| CVE-2020-21937 | CRITICAL | 9.8 | 4.8% | Jul 21, 2021 | An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.9736... |
| CVE-2020-21935 | CRITICAL | 9.8 | 4.4% | Jul 21, 2021 | A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 R... |
| CVE-2020-35427 | CRITICAL | 9.8 | 2.9% | Jul 20, 2021 | SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbit... |
| CVE-2020-7866 | CRITICAL | 9.8 | 1.0% | Jul 20, 2021 | When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper... |
| CVE-2020-5349 | CRITICAL | 9.8 | 1.2% | Jul 19, 2021 | Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential v... |
| CVE-2020-5322 | CRITICAL | 9.1 | 2.3% | Jul 19, 2021 | Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A re... |
| CVE-2020-4821 | CRITICAL | 9.8 | 2.0% | Jul 16, 2021 | IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configuration... |
| CVE-2020-11633 | CRITICAL | 9.8 | 1.9% | Jul 15, 2021 | The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfi... |
| CVE-2020-24133 | CRITICAL | 9.8 | 2.6% | Jul 14, 2021 | A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows att... |
| CVE-2020-18155 | CRITICAL | 9.8 | 1.3% | Jul 14, 2021 | SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection. |
| CVE-2020-18144 | CRITICAL | 9.8 | 1.1% | Jul 14, 2021 | SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php. |
| CVE-2020-22884 | CRITICAL | 9.8 | 2.8% | Jul 13, 2021 | Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to ... |
| CVE-2020-22875 | CRITICAL | 9.8 | 3.3% | Jul 13, 2021 | Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute ar... |
| CVE-2020-22874 | CRITICAL | 9.8 | 3.3% | Jul 13, 2021 | Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute a... |
| CVE-2020-22873 | CRITICAL | 9.8 | 2.3% | Jul 13, 2021 | Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute... |
| CVE-2020-11307 | CRITICAL | 9.8 | 0.9% | Jul 13, 2021 | Buffer overflow in modem due to improper array index check before copying into it in Snapdragon Auto, Snapdragon Compute... |
| CVE-2020-18544 | CRITICAL | 9.8 | 2.3% | Jul 12, 2021 | SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the componen... |
| CVE-2020-19038 | CRITICAL | 9.1 | 1.2% | Jul 12, 2021 | File Deletion vulnerability in Halo 0.4.3 via delBackup. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now