2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35743 | HIGH | 7.6 | 0.6% | Dec 31, 2020 | HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of spe... |
| CVE-2020-35742 | HIGH | 7.6 | 0.6% | Dec 31, 2020 | HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL para... |
| CVE-2020-35741 | MEDIUM | 6.1 | 0.6% | Dec 31, 2020 | HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inj... |
| CVE-2020-35740 | MEDIUM | 6.1 | 0.6% | Dec 31, 2020 | HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax ... |
| CVE-2020-25850 | HIGH | 7.5 | 1.1% | Dec 31, 2020 | The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can us... |
| CVE-2020-25848 | CRITICAL | 9.8 | 1.7% | Dec 31, 2020 | HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password gener... |
| CVE-2020-25846 | HIGH | 7.4 | 1.0% | Dec 31, 2020 | The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB... |
| CVE-2020-25845 | HIGH | 7.4 | 1.0% | Dec 31, 2020 | Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being re... |
| CVE-2020-25844 | CRITICAL | 9.8 | 1.9% | Dec 31, 2020 | The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a sta... |
| CVE-2020-25843 | CRITICAL | 9.8 | 1.9% | Dec 31, 2020 | NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole... |
| CVE-2020-25842 | HIGH | 7.5 | 0.5% | Dec 31, 2020 | The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access a... |
| CVE-2020-19664 | HIGH | 8.8 | 5.3% | Dec 31, 2020 | DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.... |
| CVE-2020-17363 | CRITICAL | 9.9 | 4.4% | Dec 31, 2020 | USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or n... |
| CVE-2020-16132 | — | — | — | Dec 31, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-24240. Reason: This candidate is a reservation d... |
| CVE-2020-13654 | HIGH | 7.5 | 1.9% | Dec 31, 2020 | XWiki Platform before 12.8 mishandles escaping in the property displayer. |
| CVE-2020-12658 | CRITICAL | 9.8 | 1.7% | Dec 31, 2020 | gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c... |
| CVE-2020-11947 | LOW | 3.8 | 0.5% | Dec 31, 2020 | iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated informat... |
| CVE-2020-26291 | MEDIUM | 6.5 | 1.7% | Dec 31, 2020 | URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be sp... |
| CVE-2020-27534 | MEDIUM | 5.3 | 1.7% | Dec 30, 2020 | util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-ch... |
| CVE-2020-26296 | HIGH | 8.7 | 1.4% | Dec 30, 2020 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2020-28413 | MEDIUM | 6.5 | 4.9% | Dec 30, 2020 | In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A... |
| CVE-2020-28095 | HIGH | 7.5 | 1.2% | Dec 30, 2020 | On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will tr... |
| CVE-2020-11103 | CRITICAL | 9.8 | 2.7% | Dec 30, 2020 | JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution. |
| CVE-2020-35737 | HIGH | 7.5 | 10.3% | Dec 30, 2020 | In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information... |
| CVE-2020-35173 | CRITICAL | 9.8 | 1.7% | Dec 30, 2020 | The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP s... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now