2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-37106MEDIUM5.3Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user...
CVE-2020-37095CRITICAL9.8Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute ...
CVE-2020-37079LOW3.5Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administrat...
CVE-2020-37152MEDIUM6.1PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The ap...
CVE-2020-37150HIGH8.7Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, w...
CVE-2020-37149HIGH8.8Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An...
CVE-2020-37148MEDIUM5.1P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed...
CVE-2020-37145MEDIUM5.1HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrativ...
CVE-2020-37144MEDIUM5.3Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized a...
CVE-2020-37143HIGH7.5ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application...
CVE-2020-37142HIGH8.410-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that all...
CVE-2020-37140MEDIUM5.5Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers t...
CVE-2020-37139HIGH8.4Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the applica...
CVE-2020-37138CRITICAL9.810-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that...
CVE-2020-37137CRITICAL9.8PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attacke...
CVE-2020-37136HIGH7.5ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers...
CVE-2020-37134HIGH7.5UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by man...
CVE-2020-37133HIGH7.5UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allow...
CVE-2020-37132MEDIUM5.5UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allow...
CVE-2020-37131MEDIUM5.5Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash t...
CVE-2020-37130HIGH7.5Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers ...
CVE-2020-37129CRITICAL9.8Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the Mem...
CVE-2020-37128MEDIUM6.7ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by l...
CVE-2020-37127MEDIUM6.9Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause...
CVE-2020-37126CRITICAL9.8Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attacker...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now