2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29376 | CRITICAL | 9.8 | 1.1% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a... |
| CVE-2020-26245 | CRITICAL | 9.8 | 1.9% | Nov 27, 2020 | npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. T... |
| CVE-2020-25014 | CRITICAL | 9.8 | 4.3% | Nov 27, 2020 | A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4... |
| CVE-2020-27745 | CRITICAL | 9.8 | 2.4% | Nov 27, 2020 | Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin. |
| CVE-2020-29128 | CRITICAL | 9.8 | 2.3% | Nov 26, 2020 | petl before 1.68, in some configurations, allows resolution of entities in an XML document. |
| CVE-2020-27251 | CRITICAL | 9.8 | 5.5% | Nov 26, 2020 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a re... |
| CVE-2020-29071 | CRITICAL | 9 | 1.6% | Nov 25, 2020 | An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering ... |
| CVE-2020-29062 | CRITICAL | 9.8 | 1.5% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-29061 | CRITICAL | 9.8 | 1.5% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-29060 | CRITICAL | 9.8 | 1.5% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-29059 | CRITICAL | 9.8 | 1.5% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-29058 | CRITICAL | 9.8 | 1.5% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-29056 | CRITICAL | 9.8 | 2.0% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-29054 | CRITICAL | 9.8 | 1.4% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-28329 | CRITICAL | 9.8 | 1.5% | Nov 24, 2020 | Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the... |
| CVE-2020-25159 | CRITICAL | 9.8 | 2.9% | Nov 24, 2020 | 499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker... |
| CVE-2020-28334 | CRITICAL | 9.8 | 4.7% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.... |
| CVE-2020-28333 | CRITICAL | 9.8 | 3.2% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1... |
| CVE-2020-28332 | CRITICAL | 9.8 | 1.1% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5... |
| CVE-2020-28994 | CRITICAL | 9.8 | 1.3% | Nov 24, 2020 | A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and belo... |
| CVE-2020-13942 | CRITICAL | 9.8 | 68.4% | Nov 24, 2020 | It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed... |
| CVE-2020-7378 | CRITICAL | 9.1 | 2.6% | Nov 24, 2020 | CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attac... |
| CVE-2020-4001 | CRITICAL | 9.8 | 2.9% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orches... |
| CVE-2020-29006 | CRITICAL | 9.8 | 1.2% | Nov 24, 2020 | MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyEleme... |
| CVE-2020-25475 | CRITICAL | 9.8 | 1.1% | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now