2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-37219HIGH8.7Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbi...
CVE-2020-37218HIGH8.8Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated atta...
CVE-2020-37217MEDIUM5.1Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts...
CVE-2020-37174MEDIUM5.5WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenti...
CVE-2020-37169MEDIUM6.8WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers...
CVE-2020-37168CRITICAL9.8Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force ...
CVE-2020-37216HIGH8.7Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet...
CVE-2020-37167HIGH8.6ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode inte...
CVE-2020-37215HIGH7.5MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the applica...
CVE-2020-37214HIGH8.7Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by man...
CVE-2020-37213HIGH7.5TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sendi...
CVE-2020-37212MEDIUM5.5SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to c...
CVE-2020-37211MEDIUM5.5SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a larg...
CVE-2020-37210MEDIUM5.5SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the...
CVE-2020-37209MEDIUM5.5SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to...
CVE-2020-37208MEDIUM5.5SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to cr...
CVE-2020-37207MEDIUM5.5SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to...
CVE-2020-37206MEDIUM5.5ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an ...
CVE-2020-37205MEDIUM5.5RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflo...
CVE-2020-37204MEDIUM5.5RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to cr...
CVE-2020-37203HIGH7.5Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the applicatio...
CVE-2020-37202HIGH7.5NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by suppl...
CVE-2020-37201MEDIUM5.5NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to...
CVE-2020-37200MEDIUM5.5NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to ...
CVE-2020-37199MEDIUM5.5NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to cras...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now