2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-19111CRITICAL9.8Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicio...
CVE-2020-19110CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let ...
CVE-2020-19109CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a re...
CVE-2020-19108CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remot...
CVE-2020-19107CRITICAL9.8SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote ...
CVE-2020-4979CRITICAL9.8IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to compri...
CVE-2020-13665CRITICAL9.8Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the...
CVE-2020-36333CRITICAL9.1themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard...
CVE-2020-23083CRITICAL9.8Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges ...
CVE-2020-35758CRITICAL9.8An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface...
CVE-2020-35757CRITICAL9.8An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. Th...
CVE-2020-4039CRITICAL9.1SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversa...
CVE-2020-15153CRITICAL9.8Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Secur...
CVE-2020-24918CRITICAL9.8A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to...
CVE-2020-18070CRITICAL9.1Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP reque...
CVE-2020-22807CRITICAL9.8An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
CVE-2020-35430CRITICAL9.8SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to ...
CVE-2020-21452CRITICAL9.8An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious cod...
CVE-2020-21995CRITICAL9.8Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to g...
CVE-2020-21994CRITICAL9.8AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated atta...
CVE-2020-21991CRITICAL9.8AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly c...
CVE-2020-18020CRITICAL9.8SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands int...
CVE-2020-36326CRITICAL9.8PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname...
CVE-2020-22001CRITICAL9.8HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-For...
CVE-2020-17564CRITICAL9.1Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now