2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-29472CRITICAL9.8EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admi...
CVE-2020-28188CRITICAL9.8Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inje...
CVE-2020-28187CRITICAL9.8Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, ...
CVE-2020-35665CRITICAL9.8An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in ...
CVE-2020-28074CRITICAL9.8SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass th...
CVE-2020-28073CRITICAL9.8SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authen...
CVE-2020-28070CRITICAL9.8SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GE...
CVE-2020-13968CRITICAL9.8CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parame...
CVE-2020-29552CRITICAL9.8An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0...
CVE-2020-29551CRITICAL9.1An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown t...
CVE-2020-11720CRITICAL9.8An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation,...
CVE-2020-25196CRITICAL9.8The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may ...
CVE-2020-25190CRITICAL9.8The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials o...
CVE-2020-29583CRITICAL9.8Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p...
CVE-2020-25066CRITICAL9.8A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denia...
CVE-2020-24683CRITICAL9.8The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which reli...
CVE-2020-24679CRITICAL9.8A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this fla...
CVE-2020-24675CRITICAL9.8In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations Histo...
CVE-2020-24673CRITICAL9.8In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify ...
CVE-2020-28448CRITICAL9.8This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto...
CVE-2020-8995CRITICAL9.8Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to differ...
CVE-2020-11717CRITICAL9.8An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.
CVE-2020-35605CRITICAL9.8The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code bec...
CVE-2020-35604CRITICAL9.8An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
CVE-2020-21378CRITICAL9.8SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.ph...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now