2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-28037CRITICAL9.8is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is alre...
CVE-2020-28036CRITICAL9.8wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to...
CVE-2020-28035CRITICAL9.8WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
CVE-2020-28032CRITICAL9.8WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.
CVE-2020-24881CRITICAL9.8SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
CVE-2020-23639CRITICAL9.8A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a r...
CVE-2020-14750CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions...
CVE-2020-3703CRITICAL9.8u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode r...
CVE-2020-3692CRITICAL9.8u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input valid...
CVE-2020-3673CRITICAL9.8u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check...
CVE-2020-3670CRITICAL9.1u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Informati...
CVE-2020-3657CRITICAL9.8u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from ...
CVE-2020-3654CRITICAL9.8u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying int...
CVE-2020-11172CRITICAL9.8u'fscanf reads a string from a file and stores its contents on a statically allocated stack memory which leads to stack ...
CVE-2020-11169CRITICAL9.1u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Sna...
CVE-2020-11153CRITICAL9.8u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to re...
CVE-2020-7373CRITICAL9.8vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe...
CVE-2020-27886CRITICAL9.8An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injectio...
CVE-2020-27998CRITICAL9.8An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (fo...
CVE-2020-27995CRITICAL9.8SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the se...
CVE-2020-27744CRITICAL9.8An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with r...
CVE-2020-27655CRITICAL10Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to acce...
CVE-2020-27654CRITICAL9.8Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers ...
CVE-2020-27649CRITICAL9Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allow...
CVE-2020-27648CRITICAL9Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now