2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29472 | CRITICAL | 9.8 | 4.1% | Dec 24, 2020 | EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admi... |
| CVE-2020-28188 | CRITICAL | 9.8 | 96.6% | Dec 24, 2020 | Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inje... |
| CVE-2020-28187 | CRITICAL | 9.8 | 16.4% | Dec 24, 2020 | Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, ... |
| CVE-2020-35665 | CRITICAL | 9.8 | 78.1% | Dec 23, 2020 | An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in ... |
| CVE-2020-28074 | CRITICAL | 9.8 | 2.3% | Dec 23, 2020 | SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass th... |
| CVE-2020-28073 | CRITICAL | 9.8 | 2.8% | Dec 23, 2020 | SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authen... |
| CVE-2020-28070 | CRITICAL | 9.8 | 22.9% | Dec 23, 2020 | SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GE... |
| CVE-2020-13968 | CRITICAL | 9.8 | 1.3% | Dec 23, 2020 | CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parame... |
| CVE-2020-29552 | CRITICAL | 9.8 | 4.8% | Dec 23, 2020 | An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0... |
| CVE-2020-29551 | CRITICAL | 9.1 | 2.8% | Dec 23, 2020 | An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown t... |
| CVE-2020-11720 | CRITICAL | 9.8 | 1.8% | Dec 23, 2020 | An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation,... |
| CVE-2020-25196 | CRITICAL | 9.8 | 1.4% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may ... |
| CVE-2020-25190 | CRITICAL | 9.8 | 0.7% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials o... |
| CVE-2020-29583 | CRITICAL | 9.8 | 90.0% | Dec 22, 2020 | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p... |
| CVE-2020-25066 | CRITICAL | 9.8 | 3.3% | Dec 22, 2020 | A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denia... |
| CVE-2020-24683 | CRITICAL | 9.8 | 1.4% | Dec 22, 2020 | The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which reli... |
| CVE-2020-24679 | CRITICAL | 9.8 | 1.7% | Dec 22, 2020 | A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this fla... |
| CVE-2020-24675 | CRITICAL | 9.8 | 1.2% | Dec 22, 2020 | In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations Histo... |
| CVE-2020-24673 | CRITICAL | 9.8 | 1.0% | Dec 22, 2020 | In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify ... |
| CVE-2020-28448 | CRITICAL | 9.8 | 1.4% | Dec 22, 2020 | This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto... |
| CVE-2020-8995 | CRITICAL | 9.8 | 2.1% | Dec 21, 2020 | Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to differ... |
| CVE-2020-11717 | CRITICAL | 9.8 | 2.0% | Dec 21, 2020 | An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities. |
| CVE-2020-35605 | CRITICAL | 9.8 | 3.6% | Dec 21, 2020 | The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code bec... |
| CVE-2020-35604 | CRITICAL | 9.8 | 1.6% | Dec 21, 2020 | An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used. |
| CVE-2020-21378 | CRITICAL | 9.8 | 2.1% | Dec 21, 2020 | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.ph... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now