2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12061 | CRITICAL | 9.8 | 1.9% | May 21, 2021 | An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the sec... |
| CVE-2020-36364 | CRITICAL | 9.1 | 1.8% | May 19, 2021 | An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs a... |
| CVE-2020-18178 | CRITICAL | 9.8 | 1.7% | May 18, 2021 | Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST re... |
| CVE-2020-20951 | CRITICAL | 9.8 | 4.0% | May 18, 2021 | In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files. |
| CVE-2020-4670 | CRITICAL | 9.1 | 2.5% | May 17, 2021 | IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, runnin... |
| CVE-2020-4669 | CRITICAL | 9.1 | 1.9% | May 17, 2021 | IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listenin... |
| CVE-2020-23691 | CRITICAL | 9.8 | 3.4% | May 14, 2021 | YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php. |
| CVE-2020-18166 | CRITICAL | 9.8 | 1.7% | May 14, 2021 | Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ... |
| CVE-2020-28063 | CRITICAL | 9.8 | 1.3% | May 13, 2021 | A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. |
| CVE-2020-20092 | CRITICAL | 9.8 | 1.3% | May 13, 2021 | File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type t... |
| CVE-2020-23790 | CRITICAL | 9.8 | 1.5% | May 12, 2021 | An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5. |
| CVE-2020-13873 | CRITICAL | 9.8 | 4.9% | May 12, 2021 | A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote att... |
| CVE-2020-35198 | CRITICAL | 9.8 | 2.4% | May 12, 2021 | An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a m... |
| CVE-2020-11285 | CRITICAL | 9.1 | 0.9% | May 7, 2021 | Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in S... |
| CVE-2020-11279 | CRITICAL | 9.8 | 0.8% | May 7, 2021 | Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdra... |
| CVE-2020-18890 | CRITICAL | 9.8 | 1.5% | May 6, 2021 | Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote maliciou... |
| CVE-2020-28026 | CRITICAL | 9.8 | 9.3% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable ... |
| CVE-2020-28024 | CRITICAL | 9.8 | 4.1% | May 6, 2021 | Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary co... |
| CVE-2020-28022 | CRITICAL | 9.8 | 3.0% | May 6, 2021 | Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when... |
| CVE-2020-28020 | CRITICAL | 9.8 | 7.8% | May 6, 2021 | Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute a... |
| CVE-2020-28018 | CRITICAL | 9.8 | 55.8% | May 6, 2021 | Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSS... |
| CVE-2020-28017 | CRITICAL | 9.8 | 36.1% | May 6, 2021 | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fift... |
| CVE-2020-19114 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a re... |
| CVE-2020-19113 | CRITICAL | 9.8 | 3.0% | May 6, 2021 | Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution. |
| CVE-2020-19112 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now