2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-28130CRITICAL9.8An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the...
CVE-2020-26553CRITICAL9.8An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary fil...
CVE-2020-28133CRITICAL9.8An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication ...
CVE-2020-28140CRITICAL9.8SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Product...
CVE-2020-28138CRITICAL9.8SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.
CVE-2020-27555CRITICAL9.8Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers...
CVE-2020-7774CRITICAL9.8The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
CVE-2020-27131CRITICAL9.8Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unau...
CVE-2020-27130CRITICAL9.1A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive in...
CVE-2020-27125CRITICAL9.8A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive informatio...
CVE-2020-11851CRITICAL9.8Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The...
CVE-2020-27486CRITICAL9.9Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow. The component is: ConnectIQ TVM. The attack vector is...
CVE-2020-27485CRITICAL9.9Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector ...
CVE-2020-27484CRITICAL9.9Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector i...
CVE-2020-27483CRITICAL9.9Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector ...
CVE-2020-26510CRITICAL9.8Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for depl...
CVE-2020-26508CRITICAL9.8The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials v...
CVE-2020-27422CRITICAL9.8In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an a...
CVE-2020-25952CRITICAL9.8SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allo...
CVE-2020-25207CRITICAL9.8JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
CVE-2020-5664CRITICAL9.8Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary...
CVE-2020-28642CRITICAL9.8In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it ea...
CVE-2020-8271CRITICAL9.8Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 1...
CVE-2020-7772CRITICAL9.8This affects the package doc-path before 2.1.2.
CVE-2020-28638CRITICAL9.8ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now