2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-5135CRITICAL9.8A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially exe...
CVE-2020-26948CRITICAL9.8Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
CVE-2020-26935CRITICAL9.8An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerabili...
CVE-2020-26928CRITICAL9.6Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15....
CVE-2020-26927CRITICAL9.8Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.7...
CVE-2020-26926CRITICAL9.6Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15....
CVE-2020-26919CRITICAL9.8NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.
CVE-2020-26908CRITICAL9.8Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.7...
CVE-2020-15243CRITICAL9.8Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore sh...
CVE-2020-1914CRITICAL9.8A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df62082462...
CVE-2020-25273CRITICAL9.8In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php v...
CVE-2020-15175CRITICAL9.1In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The...
CVE-2020-11800CRITICAL9.8Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
CVE-2020-13347CRITICAL9.1A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the ...
CVE-2020-26607CRITICAL9.8An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingInten...
CVE-2020-1907CRITICAL9.8A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, Wha...
CVE-2020-7741CRITICAL9.9This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.a...
CVE-2020-26574CRITICAL9.6Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript...
CVE-2020-8782CRITICAL9.8Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
CVE-2020-7465CRITICAL9.8The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet...
CVE-2020-24218CRITICAL9.8An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the p...
CVE-2020-24217CRITICAL9.8An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo...
CVE-2020-24215CRITICAL9.8An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use har...
CVE-2020-24214CRITICAL9.8An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a ...
CVE-2020-16226CRITICAL9.8Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, whic...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now