2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35565 | CRITICAL | 9.8 | 1.1% | Feb 16, 2021 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detec... |
| CVE-2020-24841 | CRITICAL | 9.8 | 1.8% | Feb 16, 2021 | PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an... |
| CVE-2020-35775 | CRITICAL | 9.8 | 13.3% | Feb 15, 2021 | CITSmart before 9.1.2.23 allows LDAP Injection. |
| CVE-2020-27868 | CRITICAL | 9.8 | 81.2% | Feb 12, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0... |
| CVE-2020-13576 | CRITICAL | 9.8 | 5.9% | Feb 10, 2021 | A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially cr... |
| CVE-2020-26299 | CRITICAL | 9.6 | 1.9% | Feb 10, 2021 | ftp-srv is an open-source FTP server designed to be simple yet configurable. In ftp-srv before version 4.4.0 there is a ... |
| CVE-2020-36244 | CRITICAL | 9.8 | 4.2% | Feb 10, 2021 | The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an a... |
| CVE-2020-28871 | CRITICAL | 9.8 | 85.8% | Feb 10, 2021 | Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the s... |
| CVE-2020-28870 | CRITICAL | 9.8 | 3.1% | Feb 10, 2021 | In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /m... |
| CVE-2020-35125 | CRITICAL | 9.6 | 2.7% | Feb 9, 2021 | A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inje... |
| CVE-2020-14343 | CRITICAL | 9.8 | 6.0% | Feb 9, 2021 | A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code e... |
| CVE-2020-28645 | CRITICAL | 9.1 | 1.2% | Feb 9, 2021 | Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to reg... |
| CVE-2020-13117 | CRITICAL | 9.8 | 68.8% | Feb 9, 2021 | Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands ... |
| CVE-2020-15798 | CRITICAL | 9.8 | 5.2% | Feb 9, 2021 | A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a)... |
| CVE-2020-7786 | CRITICAL | 9.8 | 2.0% | Feb 8, 2021 | This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js. |
| CVE-2020-7785 | CRITICAL | 9.8 | 2.5% | Feb 8, 2021 | This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js. |
| CVE-2020-7782 | CRITICAL | 9.8 | 2.5% | Feb 8, 2021 | This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection ... |
| CVE-2020-6649 | CRITICAL | 9.8 | 1.5% | Feb 8, 2021 | An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attack... |
| CVE-2020-16629 | CRITICAL | 9.8 | 1.4% | Feb 8, 2021 | PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the a... |
| CVE-2020-26051 | CRITICAL | 9.8 | 2.4% | Feb 8, 2021 | College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters ... |
| CVE-2020-11920 | CRITICAL | 9.8 | 4.2% | Feb 8, 2021 | An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in t... |
| CVE-2020-36242 | CRITICAL | 9.1 | 6.7% | Feb 7, 2021 | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB... |
| CVE-2020-10857 | CRITICAL | 9.8 | 3.0% | Feb 5, 2021 | Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remo... |
| CVE-2020-18717 | CRITICAL | 9.8 | 3.6% | Feb 5, 2021 | SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filter... |
| CVE-2020-18716 | CRITICAL | 9.8 | 1.8% | Feb 5, 2021 | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAc... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now