2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-13451CRITICAL9.8An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to over...
CVE-2020-13450CRITICAL9.8A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and ...
CVE-2020-17500CRITICAL9.8Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of...
CVE-2020-26972CRITICAL9.8The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they ...
CVE-2020-26085CRITICAL9.9Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a...
CVE-2020-36178CRITICAL9.8oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw s...
CVE-2020-36177CRITICAL9.8RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between k...
CVE-2020-27285CRITICAL9.1The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify ...
CVE-2020-10658CRITICAL9.8The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the...
CVE-2020-10656CRITICAL9.8The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the...
CVE-2020-10655CRITICAL9.8The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the...
CVE-2020-26759CRITICAL9.8clickhouse-driver before 0.1.5 allows a malicious clickhouse server to trigger a crash or execute arbitrary code (on a d...
CVE-2020-36052CRITICAL9.8Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbit...
CVE-2020-4899CRITICAL9.1IBM API Connect 5.0.0.0 through 5.0.8.10 could potentially leak sensitive information or allow for data corruption due t...
CVE-2020-26045CRITICAL9.8FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allo...
CVE-2020-29492CRITICAL10Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticate...
CVE-2020-36157CRITICAL9.8An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat...
CVE-2020-36155CRITICAL9.8An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalat...
CVE-2020-35219CRITICAL9.8The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin passw...
CVE-2020-26292CRITICAL9.8Creeper is an experimental dynamic, interpreted language. The binary release of Creeper Interpreter 1.1.3 contains poten...
CVE-2020-36112CRITICAL9.8CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pub...
CVE-2020-7771CRITICAL9.8The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.
CVE-2020-28464CRITICAL9.8This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code...
CVE-2020-35717CRITICAL9zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in web...
CVE-2020-35951CRITICAL9.9An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbit...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now