2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-37094HIGH8.6EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to...
CVE-2020-37093HIGH8.7Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve W...
CVE-2020-37088HIGH8.7School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary file...
CVE-2020-37085HIGH8.7VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by send...
CVE-2020-37083HIGH8.8PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipula...
CVE-2020-37082HIGH7.5webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database ba...
CVE-2020-37081HIGH7.1Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calend...
CVE-2020-37078HIGH8.8i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated att...
CVE-2020-37076HIGH8.2Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote att...
CVE-2020-37073HIGH8.8Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with a...
CVE-2020-37116HIGH8.8GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the...
CVE-2020-37113HIGH8.8GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renamin...
CVE-2020-37108HIGH7.1PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows r...
CVE-2020-37105HIGH7.1PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers...
CVE-2020-37102HIGH8.5Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows loc...
CVE-2020-37101HIGH8.5VPN Unlimited 6.1 contains an unquoted service path vulnerability that allows local attackers to inject malicious execut...
CVE-2020-37100HIGH8.5Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute ar...
CVE-2020-37099HIGH8.5Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in its service configuration that allows l...
CVE-2020-37098HIGH8.5Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute ar...
CVE-2020-37064HIGH8.5EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allo...
CVE-2020-37063HIGH8.5TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute a...
CVE-2020-37062HIGH8.5DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute ar...
CVE-2020-37061HIGH8.5BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute ...
CVE-2020-37055HIGH8.5SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary cod...
CVE-2020-37048HIGH8.5Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now