2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21377 | CRITICAL | 9.8 | 1.0% | Dec 21, 2020 | SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter. |
| CVE-2020-4988 | CRITICAL | 9.8 | 1.4% | Dec 21, 2020 | Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and caus... |
| CVE-2020-27846 | CRITICAL | 9.8 | 4.8% | Dec 21, 2020 | A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authenticatio... |
| CVE-2020-35276 | CRITICAL | 9.8 | 1.8% | Dec 21, 2020 | EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQ... |
| CVE-2020-35590 | CRITICAL | 9.8 | 4.3% | Dec 21, 2020 | LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per I... |
| CVE-2020-7203 | CRITICAL | 9.8 | 5.0% | Dec 18, 2020 | A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability ... |
| CVE-2020-7200 | CRITICAL | 9.8 | 81.9% | Dec 18, 2020 | A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerabili... |
| CVE-2020-14224 | CRITICAL | 9.8 | 2.2% | Dec 18, 2020 | A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthentic... |
| CVE-2020-11974 | CRITICAL | 9.8 | 7.6% | Dec 18, 2020 | In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing my... |
| CVE-2020-20300 | CRITICAL | 9.8 | 8.8% | Dec 18, 2020 | SQL injection vulnerability in the wp_where function in WeiPHP 5.0. |
| CVE-2020-20298 | CRITICAL | 9.8 | 2.7% | Dec 18, 2020 | Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 ... |
| CVE-2020-20277 | CRITICAL | 9.8 | 25.2% | Dec 18, 2020 | There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver... |
| CVE-2020-20276 | CRITICAL | 9.8 | 3.3% | Dec 18, 2020 | An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10... |
| CVE-2020-25494 | CRITICAL | 9.8 | 39.2% | Dec 18, 2020 | Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou... |
| CVE-2020-35551 | CRITICAL | 9.8 | 0.4% | Dec 18, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allo... |
| CVE-2020-35550 | CRITICAL | 9.8 | 0.6% | Dec 18, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypa... |
| CVE-2020-27780 | CRITICAL | 9.8 | 2.0% | Dec 18, 2020 | A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. Wh... |
| CVE-2020-13931 | CRITICAL | 9.8 | 3.7% | Dec 18, 2020 | If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded Activ... |
| CVE-2020-12523 | CRITICAL | 9.1 | 0.9% | Dec 17, 2020 | On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled ... |
| CVE-2020-12522 | CRITICAL | 9.8 | 2.9% | Dec 17, 2020 | The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafte... |
| CVE-2020-12519 | CRITICAL | 9.8 | 0.9% | Dec 17, 2020 | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to ope... |
| CVE-2020-12517 | CRITICAL | 9 | 1.1% | Dec 17, 2020 | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed m... |
| CVE-2020-8466 | CRITICAL | 9.8 | 63.7% | Dec 17, 2020 | A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved pas... |
| CVE-2020-8465 | CRITICAL | 9.8 | 2.6% | Dec 17, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate sy... |
| CVE-2020-35545 | CRITICAL | 9.8 | 3.8% | Dec 17, 2020 | Time-based SQL injection exists in Spotweb 1.4.9 via the query string. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now