2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28282 | CRITICAL | 9.8 | 4.0% | Dec 29, 2020 | Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may l... |
| CVE-2020-28281 | CRITICAL | 9.8 | 3.6% | Dec 29, 2020 | Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denia... |
| CVE-2020-28280 | CRITICAL | 9.8 | 2.9% | Dec 29, 2020 | Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of se... |
| CVE-2020-28279 | CRITICAL | 9.8 | 3.0% | Dec 29, 2020 | Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of ... |
| CVE-2020-28278 | CRITICAL | 9.8 | 2.9% | Dec 29, 2020 | Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service... |
| CVE-2020-28277 | CRITICAL | 9.8 | 2.9% | Dec 29, 2020 | Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service an... |
| CVE-2020-28276 | CRITICAL | 9.8 | 2.9% | Dec 29, 2020 | Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of servic... |
| CVE-2020-35769 | CRITICAL | 9.8 | 1.7% | Dec 29, 2020 | miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program. |
| CVE-2020-27172 | CRITICAL | 9.8 | 1.3% | Dec 28, 2020 | An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file resto... |
| CVE-2020-35613 | CRITICAL | 9.8 | 28.4% | Dec 28, 2020 | An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injectio... |
| CVE-2020-26290 | CRITICAL | 9.6 | 1.0% | Dec 28, 2020 | Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulner... |
| CVE-2020-26030 | CRITICAL | 9.8 | 1.3% | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted head... |
| CVE-2020-35729 | CRITICAL | 9.8 | 88.0% | Dec 27, 2020 | KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter. |
| CVE-2020-7845 | CRITICAL | 9.8 | 2.7% | Dec 27, 2020 | Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsi... |
| CVE-2020-35245 | CRITICAL | 9.8 | 1.1% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser. |
| CVE-2020-35244 | CRITICAL | 9.8 | 1.1% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup. |
| CVE-2020-35243 | CRITICAL | 9.8 | 1.1% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb. |
| CVE-2020-35242 | CRITICAL | 9.8 | 1.1% | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAnd... |
| CVE-2020-29203 | CRITICAL | 9.8 | 1.3% | Dec 26, 2020 | struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT. |
| CVE-2020-35364 | CRITICAL | 9.8 | 1.9% | Dec 26, 2020 | Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a proce... |
| CVE-2020-35575 | CRITICAL | 9.8 | 7.6% | Dec 26, 2020 | A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full adminis... |
| CVE-2020-35713 | CRITICAL | 9.8 | 32.7% | Dec 26, 2020 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new passw... |
| CVE-2020-35712 | CRITICAL | 9.8 | 1.6% | Dec 26, 2020 | Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations. |
| CVE-2020-26282 | CRITICAL | 10 | 4.6% | Dec 24, 2020 | BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data ... |
| CVE-2020-29474 | CRITICAL | 9.8 | 4.1% | Dec 24, 2020 | EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access usin... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now