2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35684HIGH7.5An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP p...
CVE-2020-35683HIGH7.5An issue was discovered in HCC Nichestack 3.0. The code that parses ICMP packets relies on an unchecked value of the IP ...
CVE-2020-22345HIGH8.8/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via s...
CVE-2020-25927HIGH7.5The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of ser...
CVE-2020-25926HIGH7.5The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The...
CVE-2020-25767HIGH7.5An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_copy_in routine for parsing DNS domain names does n...
CVE-2020-19669HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=a...
CVE-2020-22124HIGH7.5A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
CVE-2020-22122HIGH7.5A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive...
CVE-2020-22120HIGH8.8A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticate...
CVE-2020-18875HIGH8.8Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client co...
CVE-2020-18746HIGH7.2SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_lis...
CVE-2020-23334HIGH7.5A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c3...
CVE-2020-23333HIGH7.5A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 ve...
CVE-2020-23332HIGH7.5A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByt...
CVE-2020-23331HIGH7.5An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Ac...
CVE-2020-23330HIGH7.5An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize ...
CVE-2020-28594HIGH7.8A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSli...
CVE-2020-13589HIGH8.8An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management Ap...
CVE-2020-13588HIGH8.8An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management Ap...
CVE-2020-29548HIGH8.1An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline com...
CVE-2020-18759HIGH7.5An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100...
CVE-2020-18757HIGH7.5An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (D...
CVE-2020-18756HIGH7.5An arbitrary memory access vulnerability in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100 allow...
CVE-2020-18754HIGH7.5An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now