2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17563 | CRITICAL | 9.1 | 2.6% | Apr 22, 2021 | Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to ... |
| CVE-2020-7861 | CRITICAL | 9.8 | 1.5% | Apr 22, 2021 | AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy... |
| CVE-2020-23907 | CRITICAL | 9.8 | 2.6% | Apr 21, 2021 | An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible ou... |
| CVE-2020-7857 | CRITICAL | 9.8 | 1.0% | Apr 20, 2021 | A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability ex... |
| CVE-2020-35314 | CRITICAL | 9.8 | 26.9% | Apr 20, 2021 | A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al... |
| CVE-2020-35313 | CRITICAL | 9.8 | 45.2% | Apr 20, 2021 | A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in Wonder... |
| CVE-2020-26197 | CRITICAL | 9.1 | 0.6% | Apr 20, 2021 | Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may ma... |
| CVE-2020-7856 | CRITICAL | 9.8 | 0.9% | Apr 20, 2021 | A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exis... |
| CVE-2020-27241 | CRITICAL | 9.8 | 0.9% | Apr 19, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber par... |
| CVE-2020-27240 | CRITICAL | 9.8 | 0.9% | Apr 19, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus ... |
| CVE-2020-36195 | CRITICAL | 9.8 | 1.8% | Apr 17, 2021 | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming ad... |
| CVE-2020-2509 | CRITICAL | 9.8 | 34.2% | Apr 17, 2021 | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows... |
| CVE-2020-28592 | CRITICAL | 9.8 | 2.5% | Apr 15, 2021 | A heap-based buffer overflow vulnerability exists in the configuration server functionality of the Cosori Smart 5.8-Quar... |
| CVE-2020-27239 | CRITICAL | 9.8 | 0.9% | Apr 15, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus para... |
| CVE-2020-27238 | CRITICAL | 9.8 | 0.9% | Apr 15, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter i... |
| CVE-2020-27237 | CRITICAL | 9.8 | 0.9% | Apr 15, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter i... |
| CVE-2020-29592 | CRITICAL | 9.8 | 2.2% | Apr 14, 2021 | An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE... |
| CVE-2020-19778 | CRITICAL | 9.8 | 2.1% | Apr 14, 2021 | Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manip... |
| CVE-2020-27236 | CRITICAL | 9.8 | 0.9% | Apr 13, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclatu... |
| CVE-2020-27235 | CRITICAL | 9.8 | 0.9% | Apr 13, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description pa... |
| CVE-2020-27234 | CRITICAL | 9.8 | 0.9% | Apr 13, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID par... |
| CVE-2020-27233 | CRITICAL | 9.8 | 0.9% | Apr 13, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the supplierUID pa... |
| CVE-2020-27227 | CRITICAL | 9.8 | 2.9% | Apr 13, 2021 | An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can... |
| CVE-2020-15390 | CRITICAL | 9.8 | 1.3% | Apr 12, 2021 | pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerabi... |
| CVE-2020-28872 | CRITICAL | 9.8 | 3.3% | Apr 12, 2021 | An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now