2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-17563CRITICAL9.1Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to ...
CVE-2020-7861CRITICAL9.8AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy...
CVE-2020-23907CRITICAL9.8An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible ou...
CVE-2020-7857CRITICAL9.8A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability ex...
CVE-2020-35314CRITICAL9.8A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al...
CVE-2020-35313CRITICAL9.8A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in Wonder...
CVE-2020-26197CRITICAL9.1Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may ma...
CVE-2020-7856CRITICAL9.8A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exis...
CVE-2020-27241CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber par...
CVE-2020-27240CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus ...
CVE-2020-36195CRITICAL9.8An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming ad...
CVE-2020-2509CRITICAL9.8A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows...
CVE-2020-28592CRITICAL9.8A heap-based buffer overflow vulnerability exists in the configuration server functionality of the Cosori Smart 5.8-Quar...
CVE-2020-27239CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus para...
CVE-2020-27238CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter i...
CVE-2020-27237CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter i...
CVE-2020-29592CRITICAL9.8An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE...
CVE-2020-19778CRITICAL9.8Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manip...
CVE-2020-27236CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclatu...
CVE-2020-27235CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description pa...
CVE-2020-27234CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID par...
CVE-2020-27233CRITICAL9.8An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the supplierUID pa...
CVE-2020-27227CRITICAL9.8An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can...
CVE-2020-15390CRITICAL9.8pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerabi...
CVE-2020-28872CRITICAL9.8An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now