2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-24231CRITICAL9.8Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all...
CVE-2020-6875CRITICAL9.8A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mech...
CVE-2020-4493CRITICAL9.8IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a ...
CVE-2020-26527CRITICAL9.8An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random or...
CVE-2020-26525CRITICAL9.1Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the databas...
CVE-2020-15232CRITICAL9.1In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
CVE-2020-12676CRITICAL9.1FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assert...
CVE-2020-18191CRITICAL9.1GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimp...
CVE-2020-18190CRITICAL9.1Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/up...
CVE-2020-18185CRITICAL9.8class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a l...
CVE-2020-7737CRITICAL9.8All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
CVE-2020-7736CRITICAL9.8The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.
CVE-2020-24698CRITICAL9.8An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, u...
CVE-2020-12126CRITICAL9.8Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow...
CVE-2020-12125CRITICAL9.8A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.19040...
CVE-2020-12124CRITICAL9.8A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.1...
CVE-2020-26539CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V...
CVE-2020-26537CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outp...
CVE-2020-26535CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storag...
CVE-2020-26534CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Fie...
CVE-2020-26518CRITICAL9.8Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/...
CVE-2020-15533CRITICAL9.8In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalati...
CVE-2020-15227CRITICAL9.8Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passin...
CVE-2020-25990CRITICAL9.8WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Explo...
CVE-2020-12870CRITICAL9.8RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now