2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36318 | CRITICAL | 9.8 | 1.7% | Apr 11, 2021 | In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than ... |
| CVE-2020-23763 | CRITICAL | 9.8 | 1.9% | Apr 9, 2021 | SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass... |
| CVE-2020-23426 | CRITICAL | 9.8 | 3.7% | Apr 8, 2021 | zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an... |
| CVE-2020-11251 | CRITICAL | 9.1 | 0.9% | Apr 7, 2021 | Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Sn... |
| CVE-2020-11247 | CRITICAL | 9.1 | 0.9% | Apr 7, 2021 | Out of bound memory read while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute,... |
| CVE-2020-11191 | CRITICAL | 9.1 | 0.9% | Apr 7, 2021 | Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon... |
| CVE-2020-13421 | CRITICAL | 9.8 | 1.1% | Apr 6, 2021 | OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset act... |
| CVE-2020-13420 | CRITICAL | 9.8 | 2.0% | Apr 6, 2021 | OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script. |
| CVE-2020-19596 | CRITICAL | 9.8 | 1.3% | Apr 5, 2021 | Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username. |
| CVE-2020-27600 | CRITICAL | 9.8 | 13.9% | Apr 2, 2021 | HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to exe... |
| CVE-2020-21585 | CRITICAL | 9.8 | 3.2% | Apr 2, 2021 | Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module. |
| CVE-2020-35308 | CRITICAL | 9.8 | 1.5% | Mar 31, 2021 | CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute mal... |
| CVE-2020-28172 | CRITICAL | 9.8 | 3.0% | Mar 31, 2021 | A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin ... |
| CVE-2020-24391 | CRITICAL | 9.8 | 75.1% | Mar 30, 2021 | mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this m... |
| CVE-2020-35138 | CRITICAL | 9.8 | 1.2% | Mar 29, 2021 | The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the sub... |
| CVE-2020-25583 | CRITICAL | 9.8 | 1.5% | Mar 29, 2021 | In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 1... |
| CVE-2020-25577 | CRITICAL | 9.8 | 1.5% | Mar 29, 2021 | In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 1... |
| CVE-2020-24636 | CRITICAL | 9.8 | 3.3% | Mar 29, 2021 | A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products ... |
| CVE-2020-25218 | CRITICAL | 9.8 | 1.8% | Mar 29, 2021 | Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative... |
| CVE-2020-19625 | CRITICAL | 9.8 | 13.1% | Mar 26, 2021 | Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attack... |
| CVE-2020-10582 | CRITICAL | 9.8 | 1.6% | Mar 25, 2021 | A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows r... |
| CVE-2020-1946 | CRITICAL | 9.8 | 6.1% | Mar 25, 2021 | In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands w... |
| CVE-2020-7853 | CRITICAL | 9.8 | 0.8% | Mar 24, 2021 | An outbound read/write vulnerability exists in XPLATFORM that does not check offset input ranges, allowing out-of-range ... |
| CVE-2020-7839 | CRITICAL | 9.8 | 1.4% | Mar 24, 2021 | In MaEPSBroker 2.5.0.31 and prior, a command injection vulnerability caused by improper input validation checks when par... |
| CVE-2020-35337 | CRITICAL | 9.8 | 1.9% | Mar 24, 2021 | ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title para... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now