2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-36964CRITICAL9.8YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-...
CVE-2020-36962CRITICAL9.8Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers t...
CVE-2020-36961CRITICAL9.810-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows rem...
CVE-2020-36948CRITICAL9.8VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate...
CVE-2020-36941CRITICAL9.8Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports...
CVE-2020-36940CRITICAL9.8Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows a...
CVE-2020-36911CRITICAL9.8Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens ...
CVE-2020-36875CRITICAL9.3AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerabilit...
CVE-2020-36925CRITICAL9.8Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows...
CVE-2020-36923CRITICAL9.8Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to by...
CVE-2020-36912CRITICAL9.8Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script t...
CVE-2020-36904CRITICAL9.3Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrar...
CVE-2020-36902CRITICAL9.8UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escal...
CVE-2020-36898CRITICAL9.1QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint t...
CVE-2020-36897CRITICAL9.8QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx fi...
CVE-2020-36892CRITICAL9.8Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateU...
CVE-2020-36885CRITICAL9.8Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allo...
CVE-2020-36877CRITICAL9.3ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows a...
CVE-2020-36870CRITICAL9.2Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerabi...
CVE-2020-36852CRITICAL9.1The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in version...
CVE-2020-36851CRITICAL9.5Rob--W cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to ...
CVE-2020-26799CRITICAL9.8A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthe...
CVE-2020-36849CRITICAL9.8The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2020-36847CRITICAL9.8The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2...
CVE-2020-36846CRITICAL9.8A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.  Versions of IO::Compress::Brot...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now