2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-12061CRITICAL9.8An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the sec...
CVE-2020-36364CRITICAL9.1An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs a...
CVE-2020-18178CRITICAL9.8Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST re...
CVE-2020-20951CRITICAL9.8In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
CVE-2020-4670CRITICAL9.1IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, runnin...
CVE-2020-4669CRITICAL9.1IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listenin...
CVE-2020-23691CRITICAL9.8YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.
CVE-2020-18166CRITICAL9.8Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ...
CVE-2020-28063CRITICAL9.8A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
CVE-2020-20092CRITICAL9.8File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type t...
CVE-2020-23790CRITICAL9.8An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.
CVE-2020-13873CRITICAL9.8A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote att...
CVE-2020-35198CRITICAL9.8An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a m...
CVE-2020-11285CRITICAL9.1Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in S...
CVE-2020-11279CRITICAL9.8Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdra...
CVE-2020-18890CRITICAL9.8Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote maliciou...
CVE-2020-28026CRITICAL9.8Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable ...
CVE-2020-28024CRITICAL9.8Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary co...
CVE-2020-28022CRITICAL9.8Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when...
CVE-2020-28020CRITICAL9.8Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute a...
CVE-2020-28018CRITICAL9.8Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSS...
CVE-2020-28017CRITICAL9.8Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fift...
CVE-2020-19114CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a re...
CVE-2020-19113CRITICAL9.8Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.
CVE-2020-19112CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now