2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25037 | HIGH | 8.2 | 0.5% | Feb 2, 2021 | UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted ... |
| CVE-2020-36231 | MEDIUM | 4.3 | 1.2% | Feb 2, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they sh... |
| CVE-2020-14192 | MEDIUM | 4.3 | 0.9% | Feb 2, 2021 | Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Di... |
| CVE-2020-28493 | MEDIUM | 5.3 | 3.5% | Feb 1, 2021 | This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation... |
| CVE-2020-21180 | CRITICAL | 9.8 | 1.3% | Feb 1, 2021 | Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na... |
| CVE-2020-21179 | CRITICAL | 9.8 | 1.3% | Feb 1, 2021 | Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na... |
| CVE-2020-21176 | CRITICAL | 9.8 | 1.5% | Feb 1, 2021 | SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attacker... |
| CVE-2020-20296 | CRITICAL | 9.8 | 1.4% | Feb 1, 2021 | An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance para... |
| CVE-2020-20295 | CRITICAL | 9.8 | 1.4% | Feb 1, 2021 | An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail paramet... |
| CVE-2020-20294 | CRITICAL | 9.8 | 1.8% | Feb 1, 2021 | An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, maliciou... |
| CVE-2020-20290 | HIGH | 7.5 | 1.3% | Feb 1, 2021 | Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper ju... |
| CVE-2020-20289 | CRITICAL | 9.8 | 1.1% | Feb 1, 2021 | Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters,... |
| CVE-2020-20287 | CRITICAL | 9.8 | 2.8% | Feb 1, 2021 | Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request pa... |
| CVE-2020-28426 | HIGH | 7.3 | 1.9% | Feb 1, 2021 | All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId. |
| CVE-2020-25594 | MEDIUM | 5.3 | 1.4% | Feb 1, 2021 | HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requ... |
| CVE-2020-13564 | MEDIUM | 6.1 | 75.9% | Feb 1, 2021 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req... |
| CVE-2020-13563 | MEDIUM | 6.1 | 75.9% | Feb 1, 2021 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req... |
| CVE-2020-13562 | MEDIUM | 6.1 | 77.7% | Feb 1, 2021 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req... |
| CVE-2020-24271 | HIGH | 8.8 | 0.6% | Feb 1, 2021 | A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/in... |
| CVE-2020-36109 | CRITICAL | 9.8 | 4.2% | Feb 1, 2021 | ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function... |
| CVE-2020-28194 | CRITICAL | 9.8 | 2.7% | Feb 1, 2021 | Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length fie... |
| CVE-2020-26547 | CRITICAL | 9.8 | 0.5% | Feb 1, 2021 | Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows... |
| CVE-2020-15836 | CRITICAL | 9.8 | 2.2% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted... |
| CVE-2020-15835 | CRITICAL | 9.8 | 1.7% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocum... |
| CVE-2020-15834 | HIGH | 7.5 | 1.1% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now