2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-29602CRITICAL9.8The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System us...
CVE-2020-29601CRITICAL9.8The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notar...
CVE-2020-29581CRITICAL9.8The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped d...
CVE-2020-29580CRITICAL9.8The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker c...
CVE-2020-29579CRITICAL9.8The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Exp...
CVE-2020-29577CRITICAL9.8The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker ...
CVE-2020-29576CRITICAL9.8The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop D...
CVE-2020-29575CRITICAL9.8The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. System...
CVE-2020-29564CRITICAL9.8The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul ...
CVE-2020-29578CRITICAL9.8The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems u...
CVE-2020-26255CRITICAL9.1Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with...
CVE-2020-25889CRITICAL9.8Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injec...
CVE-2020-17531CRITICAL9.8A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp...
CVE-2020-29600CRITICAL9.8In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only rea...
CVE-2020-29597CRITICAL9.8IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un...
CVE-2020-29595CRITICAL9.8PlugIns\IDE_ACDStd.apl in ACDSee Photo Studio Studio Professional 2021 14.0 Build 1705 has a User Mode Write AV starting...
CVE-2020-5800CRITICAL9.8The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and ret...
CVE-2020-5799CRITICAL9.8The Eat Spray Love mobile app for both iOS and Android contains a backdoor account that, when modified, allowed privileg...
CVE-2020-25462CRITICAL9.8Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK bef...
CVE-2020-2320CRITICAL9.8Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
CVE-2020-6017CRITICAL9.8Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_Rece...
CVE-2020-29288CRITICAL9.8An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vu...
CVE-2020-29287CRITICAL9.8An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter...
CVE-2020-29285CRITICAL9.8SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter...
CVE-2020-29284CRITICAL9.8The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now