2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6874CRITICAL9.1A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so r...
CVE-2020-6873MEDIUM5.3A ZTE product has a DoS vulnerability. Because the equipment couldn’t distinguish the attack packets and normal packets ...
CVE-2020-6152HIGH7.8A code execution vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.7. A spe...
CVE-2020-6151CRITICAL9.8A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19....
CVE-2020-6144CRITICAL9.8A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable wh...
CVE-2020-6143CRITICAL9.8A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable wh...
CVE-2020-6142CRITICAL9.8A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. A specially crafted ...
CVE-2020-6140CRITICAL9.8SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email para...
CVE-2020-6139CRITICAL9.8SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The username_stf_email para...
CVE-2020-6138CRITICAL9.8SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The uname parameter in the ...
CVE-2020-6137CRITICAL9.8SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email para...
CVE-2020-5777CRITICAL9.8MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in t...
CVE-2020-5776HIGH8.8Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is poss...
CVE-2020-25070HIGH8.8USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.
CVE-2020-25069CRITICAL9.8USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view.
CVE-2020-16210CRITICAL9The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute ar...
CVE-2020-16208HIGH8.8The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different config...
CVE-2020-16206CRITICAL9The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbit...
CVE-2020-16204CRITICAL9.8The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to ...
CVE-2020-13946MEDIUM5.9In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local atta...
CVE-2020-24559HIGH7.8A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services...
CVE-2020-24558HIGH7.1A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Servi...
CVE-2020-24557HIGH7.8A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an atta...
CVE-2020-24556HIGH7.8A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business ...
CVE-2020-6141CRITICAL9.8An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted H...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now