2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28130 | CRITICAL | 9.8 | 6.3% | Nov 17, 2020 | An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the... |
| CVE-2020-26553 | CRITICAL | 9.8 | 1.7% | Nov 17, 2020 | An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary fil... |
| CVE-2020-28133 | CRITICAL | 9.8 | 2.1% | Nov 17, 2020 | An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication ... |
| CVE-2020-28140 | CRITICAL | 9.8 | 1.8% | Nov 17, 2020 | SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Product... |
| CVE-2020-28138 | CRITICAL | 9.8 | 2.0% | Nov 17, 2020 | SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php. |
| CVE-2020-27555 | CRITICAL | 9.8 | 2.5% | Nov 17, 2020 | Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers... |
| CVE-2020-7774 | CRITICAL | 9.8 | 69.1% | Nov 17, 2020 | The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. |
| CVE-2020-27131 | CRITICAL | 9.8 | 87.7% | Nov 17, 2020 | Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unau... |
| CVE-2020-27130 | CRITICAL | 9.1 | 65.9% | Nov 17, 2020 | A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive in... |
| CVE-2020-27125 | CRITICAL | 9.8 | 1.7% | Nov 17, 2020 | A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive informatio... |
| CVE-2020-11851 | CRITICAL | 9.8 | 2.8% | Nov 17, 2020 | Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The... |
| CVE-2020-27486 | CRITICAL | 9.9 | 1.9% | Nov 16, 2020 | Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow. The component is: ConnectIQ TVM. The attack vector is... |
| CVE-2020-27485 | CRITICAL | 9.9 | 1.6% | Nov 16, 2020 | Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector ... |
| CVE-2020-27484 | CRITICAL | 9.9 | 1.7% | Nov 16, 2020 | Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector i... |
| CVE-2020-27483 | CRITICAL | 9.9 | 2.1% | Nov 16, 2020 | Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector ... |
| CVE-2020-26510 | CRITICAL | 9.8 | 2.1% | Nov 16, 2020 | Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for depl... |
| CVE-2020-26508 | CRITICAL | 9.8 | 1.1% | Nov 16, 2020 | The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials v... |
| CVE-2020-27422 | CRITICAL | 9.8 | 7.8% | Nov 16, 2020 | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an a... |
| CVE-2020-25952 | CRITICAL | 9.8 | 4.1% | Nov 16, 2020 | SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allo... |
| CVE-2020-25207 | CRITICAL | 9.8 | 4.4% | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler. |
| CVE-2020-5664 | CRITICAL | 9.8 | 2.6% | Nov 16, 2020 | Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary... |
| CVE-2020-28642 | CRITICAL | 9.8 | 2.5% | Nov 16, 2020 | In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it ea... |
| CVE-2020-8271 | CRITICAL | 9.8 | 11.1% | Nov 16, 2020 | Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 1... |
| CVE-2020-7772 | CRITICAL | 9.8 | 2.7% | Nov 15, 2020 | This affects the package doc-path before 2.1.2. |
| CVE-2020-28638 | CRITICAL | 9.8 | 0.7% | Nov 13, 2020 | ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now