2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24231 | CRITICAL | 9.8 | 1.7% | Oct 5, 2020 | Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all... |
| CVE-2020-6875 | CRITICAL | 9.8 | 1.2% | Oct 5, 2020 | A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mech... |
| CVE-2020-4493 | CRITICAL | 9.8 | 2.7% | Oct 5, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a ... |
| CVE-2020-26527 | CRITICAL | 9.8 | 0.9% | Oct 2, 2020 | An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random or... |
| CVE-2020-26525 | CRITICAL | 9.1 | 25.5% | Oct 2, 2020 | Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the databas... |
| CVE-2020-15232 | CRITICAL | 9.1 | 1.3% | Oct 2, 2020 | In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style. |
| CVE-2020-12676 | CRITICAL | 9.1 | 2.9% | Oct 2, 2020 | FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assert... |
| CVE-2020-18191 | CRITICAL | 9.1 | 2.0% | Oct 2, 2020 | GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimp... |
| CVE-2020-18190 | CRITICAL | 9.1 | 1.9% | Oct 2, 2020 | Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/up... |
| CVE-2020-18185 | CRITICAL | 9.8 | 1.7% | Oct 2, 2020 | class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a l... |
| CVE-2020-7737 | CRITICAL | 9.8 | 1.3% | Oct 2, 2020 | All versions of package safetydance are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-7736 | CRITICAL | 9.8 | 1.5% | Oct 2, 2020 | The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function. |
| CVE-2020-24698 | CRITICAL | 9.8 | 3.0% | Oct 2, 2020 | An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, u... |
| CVE-2020-12126 | CRITICAL | 9.8 | 1.3% | Oct 2, 2020 | Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow... |
| CVE-2020-12125 | CRITICAL | 9.8 | 3.6% | Oct 2, 2020 | A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.19040... |
| CVE-2020-12124 | CRITICAL | 9.8 | 75.8% | Oct 2, 2020 | A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.1... |
| CVE-2020-26539 | CRITICAL | 9.8 | 2.1% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V... |
| CVE-2020-26537 | CRITICAL | 9.8 | 1.1% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outp... |
| CVE-2020-26535 | CRITICAL | 9.8 | 1.7% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storag... |
| CVE-2020-26534 | CRITICAL | 9.8 | 2.3% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Fie... |
| CVE-2020-26518 | CRITICAL | 9.8 | 2.0% | Oct 2, 2020 | Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/... |
| CVE-2020-15533 | CRITICAL | 9.8 | 4.2% | Oct 1, 2020 | In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalati... |
| CVE-2020-15227 | CRITICAL | 9.8 | 35.2% | Oct 1, 2020 | Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passin... |
| CVE-2020-25990 | CRITICAL | 9.8 | 1.6% | Oct 1, 2020 | WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Explo... |
| CVE-2020-12870 | CRITICAL | 9.8 | 1.6% | Sep 30, 2020 | RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now