2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-35565CRITICAL9.8An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detec...
CVE-2020-24841CRITICAL9.8PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an...
CVE-2020-35775CRITICAL9.8CITSmart before 9.1.2.23 allows LDAP Injection.
CVE-2020-27868CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0...
CVE-2020-13576CRITICAL9.8A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially cr...
CVE-2020-26299CRITICAL9.6ftp-srv is an open-source FTP server designed to be simple yet configurable. In ftp-srv before version 4.4.0 there is a ...
CVE-2020-36244CRITICAL9.8The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an a...
CVE-2020-28871CRITICAL9.8Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the s...
CVE-2020-28870CRITICAL9.8In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /m...
CVE-2020-35125CRITICAL9.6A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inje...
CVE-2020-14343CRITICAL9.8A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code e...
CVE-2020-28645CRITICAL9.1Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to reg...
CVE-2020-13117CRITICAL9.8Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands ...
CVE-2020-15798CRITICAL9.8A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a)...
CVE-2020-7786CRITICAL9.8This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
CVE-2020-7785CRITICAL9.8This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
CVE-2020-7782CRITICAL9.8This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection ...
CVE-2020-6649CRITICAL9.8An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attack...
CVE-2020-16629CRITICAL9.8PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the a...
CVE-2020-26051CRITICAL9.8College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters ...
CVE-2020-11920CRITICAL9.8An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in t...
CVE-2020-36242CRITICAL9.1In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB...
CVE-2020-10857CRITICAL9.8Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remo...
CVE-2020-18717CRITICAL9.8SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filter...
CVE-2020-18716CRITICAL9.8SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAc...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now