2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29283 | CRITICAL | 9.8 | 1.3% | Dec 2, 2020 | An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parame... |
| CVE-2020-29282 | CRITICAL | 9.8 | 2.7% | Dec 2, 2020 | SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication. |
| CVE-2020-29280 | CRITICAL | 9.8 | 1.9% | Dec 2, 2020 | The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. |
| CVE-2020-29279 | CRITICAL | 9.8 | 52.9% | Dec 2, 2020 | PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 7... |
| CVE-2020-29389 | CRITICAL | 9.8 | 1.7% | Dec 2, 2020 | The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Li... |
| CVE-2020-28273 | CRITICAL | 9.8 | 3.9% | Dec 2, 2020 | Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service ... |
| CVE-2020-28272 | CRITICAL | 9.8 | 3.3% | Dec 2, 2020 | Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service ... |
| CVE-2020-7199 | CRITICAL | 9.8 | 9.2% | Dec 2, 2020 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr... |
| CVE-2020-6018 | CRITICAL | 9.8 | 3.1% | Dec 2, 2020 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_D... |
| CVE-2020-14260 | CRITICAL | 9.8 | 1.4% | Dec 2, 2020 | HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successf... |
| CVE-2020-6880 | CRITICAL | 9.8 | 1.2% | Dec 1, 2020 | A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending m... |
| CVE-2020-28971 | CRITICAL | 9.8 | 3.8% | Dec 1, 2020 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vuln... |
| CVE-2020-28970 | CRITICAL | 9.8 | 3.9% | Dec 1, 2020 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vuln... |
| CVE-2020-28940 | CRITICAL | 9.8 | 3.9% | Dec 1, 2020 | On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerabi... |
| CVE-2020-7548 | CRITICAL | 9.8 | 1.4% | Dec 1, 2020 | A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (... |
| CVE-2020-7533 | CRITICAL | 9.8 | 2.3% | Dec 1, 2020 | CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver witho... |
| CVE-2020-26762 | CRITICAL | 9.8 | 2.2% | Dec 1, 2020 | A stack-based buffer-overflow exists in Edimax IP-Camera IC-3116W (v3.06) and IC-3140W (v3.07), which allows an unauthen... |
| CVE-2020-29390 | CRITICAL | 9.8 | 36.7% | Nov 30, 2020 | Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that co... |
| CVE-2020-28926 | CRITICAL | 9.8 | 14.3% | Nov 30, 2020 | ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to t... |
| CVE-2020-25537 | CRITICAL | 9.8 | 1.8% | Nov 30, 2020 | File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain serv... |
| CVE-2020-4627 | CRITICAL | 9 | 1.6% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitr... |
| CVE-2020-27660 | CRITICAL | 9.8 | 4.6% | Nov 30, 2020 | SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute a... |
| CVE-2020-29127 | CRITICAL | 9.8 | 4.4% | Nov 30, 2020 | An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as... |
| CVE-2020-29381 | CRITICAL | 9.8 | 2.3% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a... |
| CVE-2020-29377 | CRITICAL | 9.8 | 1.3% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 OLT devices. The string K0LTdi@gnos312$ is compared to the password pro... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now