2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-28282CRITICAL9.8Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may l...
CVE-2020-28281CRITICAL9.8Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denia...
CVE-2020-28280CRITICAL9.8Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of se...
CVE-2020-28279CRITICAL9.8Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of ...
CVE-2020-28278CRITICAL9.8Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service...
CVE-2020-28277CRITICAL9.8Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service an...
CVE-2020-28276CRITICAL9.8Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of servic...
CVE-2020-35769CRITICAL9.8miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.
CVE-2020-27172CRITICAL9.8An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file resto...
CVE-2020-35613CRITICAL9.8An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injectio...
CVE-2020-26290CRITICAL9.6Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulner...
CVE-2020-26030CRITICAL9.8An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted head...
CVE-2020-35729CRITICAL9.8KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
CVE-2020-7845CRITICAL9.8Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsi...
CVE-2020-35245CRITICAL9.8Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
CVE-2020-35244CRITICAL9.8Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
CVE-2020-35243CRITICAL9.8Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
CVE-2020-35242CRITICAL9.8Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAnd...
CVE-2020-29203CRITICAL9.8struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT.
CVE-2020-35364CRITICAL9.8Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a proce...
CVE-2020-35575CRITICAL9.8A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full adminis...
CVE-2020-35713CRITICAL9.8Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new passw...
CVE-2020-35712CRITICAL9.8Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
CVE-2020-26282CRITICAL10BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data ...
CVE-2020-29474CRITICAL9.8EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access usin...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now