2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-18714CRITICAL9.8SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordMo...
CVE-2020-18713CRITICAL9.8SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in custom...
CVE-2020-10539CRITICAL9.8An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user...
CVE-2020-14245CRITICAL9.8HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable ...
CVE-2020-17523CRITICAL9.8Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentica...
CVE-2020-35481CRITICAL9.8SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
CVE-2020-2507CRITICAL9.8The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerabili...
CVE-2020-2506CRITICAL9.8The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulne...
CVE-2020-28653CRITICAL9.8Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v...
CVE-2020-29165CRITICAL9.8PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotel...
CVE-2020-28144CRITICAL9.8Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 ...
CVE-2020-7775CRITICAL9.8This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments...
CVE-2020-15097CRITICAL9.1loklak is an open-source server application which is able to collect messages from various sources, including twitter. T...
CVE-2020-18568CRITICAL9.8The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause ...
CVE-2020-25506CRITICAL9.8D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead ...
CVE-2020-1896CRITICAL9.8A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7...
CVE-2020-21180CRITICAL9.8Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na...
CVE-2020-21179CRITICAL9.8Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na...
CVE-2020-21176CRITICAL9.8SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attacker...
CVE-2020-20296CRITICAL9.8An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance para...
CVE-2020-20295CRITICAL9.8An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail paramet...
CVE-2020-20294CRITICAL9.8An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, maliciou...
CVE-2020-20289CRITICAL9.8Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters,...
CVE-2020-20287CRITICAL9.8Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request pa...
CVE-2020-36109CRITICAL9.8ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now