2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-18714 | CRITICAL | 9.8 | 1.3% | Feb 5, 2021 | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordMo... |
| CVE-2020-18713 | CRITICAL | 9.8 | 1.8% | Feb 5, 2021 | SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in custom... |
| CVE-2020-10539 | CRITICAL | 9.8 | 1.5% | Feb 5, 2021 | An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user... |
| CVE-2020-14245 | CRITICAL | 9.8 | 1.2% | Feb 4, 2021 | HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable ... |
| CVE-2020-17523 | CRITICAL | 9.8 | 85.9% | Feb 3, 2021 | Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentica... |
| CVE-2020-35481 | CRITICAL | 9.8 | 1.3% | Feb 3, 2021 | SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection. |
| CVE-2020-2507 | CRITICAL | 9.8 | 2.7% | Feb 3, 2021 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerabili... |
| CVE-2020-2506 | CRITICAL | 9.8 | 2.0% | Feb 3, 2021 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulne... |
| CVE-2020-28653 | CRITICAL | 9.8 | 78.7% | Feb 3, 2021 | Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v... |
| CVE-2020-29165 | CRITICAL | 9.8 | 1.7% | Feb 3, 2021 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotel... |
| CVE-2020-28144 | CRITICAL | 9.8 | 2.1% | Feb 3, 2021 | Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 ... |
| CVE-2020-7775 | CRITICAL | 9.8 | 1.3% | Feb 2, 2021 | This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments... |
| CVE-2020-15097 | CRITICAL | 9.1 | 2.1% | Feb 2, 2021 | loklak is an open-source server application which is able to collect messages from various sources, including twitter. T... |
| CVE-2020-18568 | CRITICAL | 9.8 | 14.6% | Feb 2, 2021 | The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause ... |
| CVE-2020-25506 | CRITICAL | 9.8 | 100.0% | Feb 2, 2021 | D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead ... |
| CVE-2020-1896 | CRITICAL | 9.8 | 2.4% | Feb 2, 2021 | A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7... |
| CVE-2020-21180 | CRITICAL | 9.8 | 1.3% | Feb 1, 2021 | Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na... |
| CVE-2020-21179 | CRITICAL | 9.8 | 1.3% | Feb 1, 2021 | Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the na... |
| CVE-2020-21176 | CRITICAL | 9.8 | 1.5% | Feb 1, 2021 | SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attacker... |
| CVE-2020-20296 | CRITICAL | 9.8 | 1.4% | Feb 1, 2021 | An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance para... |
| CVE-2020-20295 | CRITICAL | 9.8 | 1.4% | Feb 1, 2021 | An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail paramet... |
| CVE-2020-20294 | CRITICAL | 9.8 | 1.8% | Feb 1, 2021 | An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, maliciou... |
| CVE-2020-20289 | CRITICAL | 9.8 | 1.1% | Feb 1, 2021 | Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters,... |
| CVE-2020-20287 | CRITICAL | 9.8 | 2.8% | Feb 1, 2021 | Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request pa... |
| CVE-2020-36109 | CRITICAL | 9.8 | 4.2% | Feb 1, 2021 | ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now