2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-37172CRITICAL9.8AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by...
CVE-2020-37158HIGH8.8AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by...
CVE-2020-37156MEDIUM6.9BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard wi...
CVE-2020-37153CRITICAL9.8ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configu...
CVE-2020-37104HIGH8.7ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database ...
CVE-2020-37171MEDIUM5.5TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows...
CVE-2020-37170MEDIUM5.5TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy address configuration that allows ...
CVE-2020-37166MEDIUM5.5AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attac...
CVE-2020-37165MEDIUM5.5AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by ...
CVE-2020-37164MEDIUM5.5AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by ...
CVE-2020-37163HIGH8.8QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries throu...
CVE-2020-37162CRITICAL9.8Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attacke...
CVE-2020-37161CRITICAL9.8Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code b...
CVE-2020-37160HIGH8.5SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder...
CVE-2020-37159CRITICAL9.8Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by ...
CVE-2020-37157HIGH8.7DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrie...
CVE-2020-37155HIGH7.5Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash th...
CVE-2020-37154HIGH7.1eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows atta...
CVE-2020-37147HIGH7.1ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers ...
CVE-2020-37146HIGH8.7ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers...
CVE-2020-37141HIGH8.8AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' p...
CVE-2020-37135CRITICAL9.3AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using...
CVE-2020-37122HIGH7.5SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the applica...
CVE-2020-37109HIGH7.5aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by ov...
CVE-2020-37107HIGH7.5Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now