2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-37104HIGH8.7ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database ...
CVE-2020-37163HIGH8.8QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries throu...
CVE-2020-37160HIGH8.5SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder...
CVE-2020-37157HIGH8.7DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrie...
CVE-2020-37155HIGH7.5Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash th...
CVE-2020-37154HIGH7.1eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows atta...
CVE-2020-37147HIGH7.1ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers ...
CVE-2020-37146HIGH8.7ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers...
CVE-2020-37141HIGH8.8AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' p...
CVE-2020-37122HIGH7.5SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the applica...
CVE-2020-37109HIGH7.5aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by ov...
CVE-2020-37107HIGH7.5Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting...
CVE-2020-37150HIGH8.7Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, w...
CVE-2020-37149HIGH8.8Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An...
CVE-2020-37143HIGH7.5ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application...
CVE-2020-37142HIGH8.410-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that all...
CVE-2020-37139HIGH8.4Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the applica...
CVE-2020-37136HIGH7.5ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers...
CVE-2020-37134HIGH7.5UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by man...
CVE-2020-37133HIGH7.5UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allow...
CVE-2020-37130HIGH7.5Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers ...
CVE-2020-37117HIGH8.8jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated adm...
CVE-2020-37151HIGH7.5phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter th...
CVE-2020-37084HIGH7.2School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitr...
CVE-2020-37097HIGH8.7Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now