2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36964 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-... |
| CVE-2020-36962 | CRITICAL | 9.8 | 10.7% | Jan 28, 2026 | Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers t... |
| CVE-2020-36961 | CRITICAL | 9.8 | 0.5% | Jan 28, 2026 | 10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows rem... |
| CVE-2020-36948 | CRITICAL | 9.8 | 0.6% | Jan 27, 2026 | VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate... |
| CVE-2020-36941 | CRITICAL | 9.8 | 0.5% | Jan 27, 2026 | Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports... |
| CVE-2020-36940 | CRITICAL | 9.8 | 0.2% | Jan 27, 2026 | Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows a... |
| CVE-2020-36911 | CRITICAL | 9.8 | 10.4% | Jan 13, 2026 | Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens ... |
| CVE-2020-36875 | CRITICAL | 9.3 | 0.7% | Jan 9, 2026 | AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerabilit... |
| CVE-2020-36925 | CRITICAL | 9.8 | 0.6% | Jan 6, 2026 | Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows... |
| CVE-2020-36923 | CRITICAL | 9.8 | 0.9% | Jan 6, 2026 | Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to by... |
| CVE-2020-36912 | CRITICAL | 9.8 | 0.4% | Jan 6, 2026 | Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script t... |
| CVE-2020-36904 | CRITICAL | 9.3 | 0.4% | Dec 31, 2025 | Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrar... |
| CVE-2020-36902 | CRITICAL | 9.8 | 1.0% | Dec 10, 2025 | UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escal... |
| CVE-2020-36898 | CRITICAL | 9.1 | 1.5% | Dec 10, 2025 | QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint t... |
| CVE-2020-36897 | CRITICAL | 9.8 | 1.1% | Dec 10, 2025 | QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx fi... |
| CVE-2020-36892 | CRITICAL | 9.8 | 0.9% | Dec 10, 2025 | Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateU... |
| CVE-2020-36885 | CRITICAL | 9.8 | 1.0% | Dec 10, 2025 | Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allo... |
| CVE-2020-36877 | CRITICAL | 9.3 | 0.6% | Dec 5, 2025 | ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows a... |
| CVE-2020-36870 | CRITICAL | 9.2 | 0.7% | Nov 7, 2025 | Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerabi... |
| CVE-2020-36852 | CRITICAL | 9.1 | 0.3% | Oct 1, 2025 | The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in version... |
| CVE-2020-36851 | CRITICAL | 9.5 | 1.0% | Sep 25, 2025 | Rob--W cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to ... |
| CVE-2020-26799 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthe... |
| CVE-2020-36849 | CRITICAL | 9.8 | 4.7% | Jul 12, 2025 | The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2020-36847 | CRITICAL | 9.8 | 12.6% | Jul 12, 2025 | The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2... |
| CVE-2020-36846 | CRITICAL | 9.8 | 0.5% | May 30, 2025 | A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brot... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now