2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-29658CRITICAL9.8Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to...
CVE-2020-8298CRITICAL9.8fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `cop...
CVE-2020-35636CRITICAL9.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_...
CVE-2020-35628CRITICAL9.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-28636CRITICAL9.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-28601CRITICAL9.8A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v...
CVE-2020-24914CRITICAL9.8A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of th...
CVE-2020-24913CRITICAL9.8A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows ...
CVE-2020-29047CRITICAL9.8The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an...
CVE-2020-28657CRITICAL9.8In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL...
CVE-2020-28199CRITICAL9.1best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor.
CVE-2020-23534CRITICAL9.8A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
CVE-2020-27224CRITICAL9.6In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute ...
CVE-2020-28429CRITICAL9.8All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geoj...
CVE-2020-21224CRITICAL9.8A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a maliciou...
CVE-2020-11283CRITICAL9.8A buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Comp...
CVE-2020-11276CRITICAL9.1Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper ...
CVE-2020-11275CRITICAL9.1Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beaco...
CVE-2020-11272CRITICAL9.8Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a sta...
CVE-2020-11170CRITICAL9.8Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header ex...
CVE-2020-11163CRITICAL9.8Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters...
CVE-2020-28499CRITICAL9.8All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .
CVE-2020-28490CRITICAL9.8The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For exam...
CVE-2020-35339CRITICAL9.8In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController...
CVE-2020-2501CRITICAL9.8A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. I...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now