2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35743HIGH7.6HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of spe...
CVE-2020-35742HIGH7.6HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL para...
CVE-2020-35741MEDIUM6.1HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inj...
CVE-2020-35740MEDIUM6.1HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax ...
CVE-2020-25850HIGH7.5The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can us...
CVE-2020-25848CRITICAL9.8HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password gener...
CVE-2020-25846HIGH7.4The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB...
CVE-2020-25845HIGH7.4Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being re...
CVE-2020-25844CRITICAL9.8The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a sta...
CVE-2020-25843CRITICAL9.8NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole...
CVE-2020-25842HIGH7.5The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access a...
CVE-2020-19664HIGH8.8DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction....
CVE-2020-17363CRITICAL9.9USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or n...
CVE-2020-16132Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-24240. Reason: This candidate is a reservation d...
CVE-2020-13654HIGH7.5XWiki Platform before 12.8 mishandles escaping in the property displayer.
CVE-2020-12658CRITICAL9.8gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c...
CVE-2020-11947LOW3.8iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated informat...
CVE-2020-26291MEDIUM6.5URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be sp...
CVE-2020-27534MEDIUM5.3util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-ch...
CVE-2020-26296HIGH8.7Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2020-28413MEDIUM6.5In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A...
CVE-2020-28095HIGH7.5On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will tr...
CVE-2020-11103CRITICAL9.8JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.
CVE-2020-35737HIGH7.5In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information...
CVE-2020-35173CRITICAL9.8The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP s...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now