2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-7788CRITICAL9.8This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it ...
CVE-2020-13556CRITICAL9.8An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and de...
CVE-2020-24634CRITICAL9.8An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Ar...
CVE-2020-24633CRITICAL9.8There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending e...
CVE-2020-17530CRITICAL9.8Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected ...
CVE-2020-7540CRITICAL9.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy O...
CVE-2020-28215CRITICAL9.8A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide ...
CVE-2020-29311CRITICAL9.8Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside th...
CVE-2020-26201CRITICAL9.8Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. Th...
CVE-2020-19527CRITICAL9.8iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/inst...
CVE-2020-19142CRITICAL9.8iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install...
CVE-2020-16608CRITICAL9.6Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in web...
CVE-2020-29667CRITICAL9.8In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSI...
CVE-2020-24445CRITICAL9AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS...
CVE-2020-17142CRITICAL9.1Microsoft Exchange Remote Code Execution Vulnerability
CVE-2020-17132CRITICAL9.1Microsoft Exchange Remote Code Execution Vulnerability
CVE-2020-29659CRITICAL9.8A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execut...
CVE-2020-26838CRITICAL9.1SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions...
CVE-2020-26837CRITICAL9.1SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious...
CVE-2020-26831CRITICAL9.6SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML ...
CVE-2020-26829CRITICAL10SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary conne...
CVE-2020-17529CRITICAL9.8Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0....
CVE-2020-17528CRITICAL9.1Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0....
CVE-2020-29657CRITICAL9.1In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file.
CVE-2020-28274CRITICAL9.8Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now