2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29602 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System us... |
| CVE-2020-29601 | CRITICAL | 9.8 | 2.3% | Dec 8, 2020 | The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notar... |
| CVE-2020-29581 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped d... |
| CVE-2020-29580 | CRITICAL | 9.8 | 2.3% | Dec 8, 2020 | The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker c... |
| CVE-2020-29579 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Exp... |
| CVE-2020-29577 | CRITICAL | 9.8 | 2.3% | Dec 8, 2020 | The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker ... |
| CVE-2020-29576 | CRITICAL | 9.8 | 3.0% | Dec 8, 2020 | The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop D... |
| CVE-2020-29575 | CRITICAL | 9.8 | 2.9% | Dec 8, 2020 | The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. System... |
| CVE-2020-29564 | CRITICAL | 9.8 | 6.2% | Dec 8, 2020 | The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul ... |
| CVE-2020-29578 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems u... |
| CVE-2020-26255 | CRITICAL | 9.1 | 1.5% | Dec 8, 2020 | Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with... |
| CVE-2020-25889 | CRITICAL | 9.8 | 2.7% | Dec 8, 2020 | Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injec... |
| CVE-2020-17531 | CRITICAL | 9.8 | 9.7% | Dec 8, 2020 | A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp... |
| CVE-2020-29600 | CRITICAL | 9.8 | 2.9% | Dec 7, 2020 | In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only rea... |
| CVE-2020-29597 | CRITICAL | 9.8 | 71.7% | Dec 7, 2020 | IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un... |
| CVE-2020-29595 | CRITICAL | 9.8 | 1.2% | Dec 7, 2020 | PlugIns\IDE_ACDStd.apl in ACDSee Photo Studio Studio Professional 2021 14.0 Build 1705 has a User Mode Write AV starting... |
| CVE-2020-5800 | CRITICAL | 9.8 | 1.6% | Dec 7, 2020 | The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and ret... |
| CVE-2020-5799 | CRITICAL | 9.8 | 1.2% | Dec 7, 2020 | The Eat Spray Love mobile app for both iOS and Android contains a backdoor account that, when modified, allowed privileg... |
| CVE-2020-25462 | CRITICAL | 9.8 | 1.9% | Dec 4, 2020 | Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK bef... |
| CVE-2020-2320 | CRITICAL | 9.8 | 0.9% | Dec 3, 2020 | Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads. |
| CVE-2020-6017 | CRITICAL | 9.8 | 3.1% | Dec 3, 2020 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_Rece... |
| CVE-2020-29288 | CRITICAL | 9.8 | 2.6% | Dec 2, 2020 | An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vu... |
| CVE-2020-29287 | CRITICAL | 9.8 | 2.7% | Dec 2, 2020 | An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter... |
| CVE-2020-29285 | CRITICAL | 9.8 | 1.3% | Dec 2, 2020 | SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter... |
| CVE-2020-29284 | CRITICAL | 9.8 | 6.1% | Dec 2, 2020 | The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now