2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19111 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicio... |
| CVE-2020-19110 | CRITICAL | 9.8 | 1.6% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let ... |
| CVE-2020-19109 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a re... |
| CVE-2020-19108 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remot... |
| CVE-2020-19107 | CRITICAL | 9.8 | 1.9% | May 6, 2021 | SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote ... |
| CVE-2020-4979 | CRITICAL | 9.8 | 1.6% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to compri... |
| CVE-2020-13665 | CRITICAL | 9.8 | 1.3% | May 5, 2021 | Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the... |
| CVE-2020-36333 | CRITICAL | 9.1 | 3.4% | May 5, 2021 | themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard... |
| CVE-2020-23083 | CRITICAL | 9.8 | 3.7% | May 3, 2021 | Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges ... |
| CVE-2020-35758 | CRITICAL | 9.8 | 1.6% | May 3, 2021 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface... |
| CVE-2020-35757 | CRITICAL | 9.8 | 1.8% | May 3, 2021 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. Th... |
| CVE-2020-4039 | CRITICAL | 9.1 | 1.4% | Apr 30, 2021 | SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversa... |
| CVE-2020-15153 | CRITICAL | 9.8 | 2.4% | Apr 30, 2021 | Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Secur... |
| CVE-2020-24918 | CRITICAL | 9.8 | 4.4% | Apr 30, 2021 | A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to... |
| CVE-2020-18070 | CRITICAL | 9.1 | 2.2% | Apr 30, 2021 | Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP reque... |
| CVE-2020-22807 | CRITICAL | 9.8 | 1.3% | Apr 29, 2021 | An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. |
| CVE-2020-35430 | CRITICAL | 9.8 | 1.1% | Apr 29, 2021 | SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to ... |
| CVE-2020-21452 | CRITICAL | 9.8 | 1.1% | Apr 29, 2021 | An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious cod... |
| CVE-2020-21995 | CRITICAL | 9.8 | 2.0% | Apr 29, 2021 | Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to g... |
| CVE-2020-21994 | CRITICAL | 9.8 | 3.7% | Apr 28, 2021 | AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated atta... |
| CVE-2020-21991 | CRITICAL | 9.8 | 2.9% | Apr 28, 2021 | AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly c... |
| CVE-2020-18020 | CRITICAL | 9.8 | 3.8% | Apr 28, 2021 | SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands int... |
| CVE-2020-36326 | CRITICAL | 9.8 | 3.1% | Apr 28, 2021 | PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname... |
| CVE-2020-22001 | CRITICAL | 9.8 | 3.4% | Apr 27, 2021 | HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-For... |
| CVE-2020-17564 | CRITICAL | 9.1 | 2.6% | Apr 22, 2021 | Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now