2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29658 | CRITICAL | 9.8 | 3.7% | Mar 5, 2021 | Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to... |
| CVE-2020-8298 | CRITICAL | 9.8 | 11.2% | Mar 4, 2021 | fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `cop... |
| CVE-2020-35636 | CRITICAL | 9.8 | 3.3% | Mar 4, 2021 | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_... |
| CVE-2020-35628 | CRITICAL | 9.8 | 2.9% | Mar 4, 2021 | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v... |
| CVE-2020-28636 | CRITICAL | 9.8 | 2.9% | Mar 4, 2021 | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v... |
| CVE-2020-28601 | CRITICAL | 9.8 | 2.9% | Mar 4, 2021 | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v... |
| CVE-2020-24914 | CRITICAL | 9.8 | 5.6% | Mar 4, 2021 | A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of th... |
| CVE-2020-24913 | CRITICAL | 9.8 | 43.3% | Mar 4, 2021 | A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows ... |
| CVE-2020-29047 | CRITICAL | 9.8 | 14.3% | Mar 3, 2021 | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an... |
| CVE-2020-28657 | CRITICAL | 9.8 | 1.7% | Mar 2, 2021 | In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL... |
| CVE-2020-28199 | CRITICAL | 9.1 | 1.7% | Feb 26, 2021 | best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor. |
| CVE-2020-23534 | CRITICAL | 9.8 | 1.3% | Feb 25, 2021 | A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter. |
| CVE-2020-27224 | CRITICAL | 9.6 | 2.4% | Feb 24, 2021 | In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute ... |
| CVE-2020-28429 | CRITICAL | 9.8 | 63.3% | Feb 23, 2021 | All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geoj... |
| CVE-2020-21224 | CRITICAL | 9.8 | 38.7% | Feb 22, 2021 | A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a maliciou... |
| CVE-2020-11283 | CRITICAL | 9.8 | 0.7% | Feb 22, 2021 | A buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Comp... |
| CVE-2020-11276 | CRITICAL | 9.1 | 0.8% | Feb 22, 2021 | Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper ... |
| CVE-2020-11275 | CRITICAL | 9.1 | 0.8% | Feb 22, 2021 | Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beaco... |
| CVE-2020-11272 | CRITICAL | 9.8 | 0.8% | Feb 22, 2021 | Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a sta... |
| CVE-2020-11170 | CRITICAL | 9.8 | 0.8% | Feb 22, 2021 | Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header ex... |
| CVE-2020-11163 | CRITICAL | 9.8 | 0.8% | Feb 22, 2021 | Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters... |
| CVE-2020-28499 | CRITICAL | 9.8 | 1.4% | Feb 18, 2021 | All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge . |
| CVE-2020-28490 | CRITICAL | 9.8 | 2.5% | Feb 18, 2021 | The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For exam... |
| CVE-2020-35339 | CRITICAL | 9.8 | 4.4% | Feb 17, 2021 | In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController... |
| CVE-2020-2501 | CRITICAL | 9.8 | 2.9% | Feb 17, 2021 | A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. I... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now