2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-21377CRITICAL9.8SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.
CVE-2020-4988CRITICAL9.8Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and caus...
CVE-2020-27846CRITICAL9.8A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authenticatio...
CVE-2020-35276CRITICAL9.8EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQ...
CVE-2020-35590CRITICAL9.8LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per I...
CVE-2020-7203CRITICAL9.8A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability ...
CVE-2020-7200CRITICAL9.8A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerabili...
CVE-2020-14224CRITICAL9.8A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthentic...
CVE-2020-11974CRITICAL9.8In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing my...
CVE-2020-20300CRITICAL9.8SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
CVE-2020-20298CRITICAL9.8Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 ...
CVE-2020-20277CRITICAL9.8There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver...
CVE-2020-20276CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10...
CVE-2020-25494CRITICAL9.8Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou...
CVE-2020-35551CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allo...
CVE-2020-35550CRITICAL9.8An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypa...
CVE-2020-27780CRITICAL9.8A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. Wh...
CVE-2020-13931CRITICAL9.8If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded Activ...
CVE-2020-12523CRITICAL9.1On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled ...
CVE-2020-12522CRITICAL9.8The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafte...
CVE-2020-12519CRITICAL9.8On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to ope...
CVE-2020-12517CRITICAL9On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed m...
CVE-2020-8466CRITICAL9.8A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved pas...
CVE-2020-8465CRITICAL9.8A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate sy...
CVE-2020-35545CRITICAL9.8Time-based SQL injection exists in Spotweb 1.4.9 via the query string.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now