2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25037HIGH8.2UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted ...
CVE-2020-36231MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they sh...
CVE-2020-14192MEDIUM4.3Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Di...
CVE-2020-28493MEDIUM5.3This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation...
CVE-2020-21180CRITICAL9.8Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na...
CVE-2020-21179CRITICAL9.8Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na...
CVE-2020-21176CRITICAL9.8SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attacker...
CVE-2020-20296CRITICAL9.8An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance para...
CVE-2020-20295CRITICAL9.8An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail paramet...
CVE-2020-20294CRITICAL9.8An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, maliciou...
CVE-2020-20290HIGH7.5Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper ju...
CVE-2020-20289CRITICAL9.8Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters,...
CVE-2020-20287CRITICAL9.8Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request pa...
CVE-2020-28426HIGH7.3All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.
CVE-2020-25594MEDIUM5.3HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requ...
CVE-2020-13564MEDIUM6.1A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req...
CVE-2020-13563MEDIUM6.1A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req...
CVE-2020-13562MEDIUM6.1A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req...
CVE-2020-24271HIGH8.8A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/in...
CVE-2020-36109CRITICAL9.8ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function...
CVE-2020-28194CRITICAL9.8Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length fie...
CVE-2020-26547CRITICAL9.8Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows...
CVE-2020-15836CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted...
CVE-2020-15835CRITICAL9.8An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocum...
CVE-2020-15834HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now