2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-37021HIGH8.510-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local a...
CVE-2020-37020HIGH8.5SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by...
CVE-2020-37017HIGH8.5CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary ...
CVE-2020-37016HIGH8.5BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with eleva...
CVE-2020-37015HIGH7.5The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthent...
CVE-2020-37013HIGH8.4Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters th...
CVE-2020-37011HIGH8.4Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds wri...
CVE-2020-37009HIGH8.8MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized user...
CVE-2020-37008HIGH8.7EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries i...
CVE-2020-37006HIGH8.2berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to man...
CVE-2020-37005HIGH7.1TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumer...
CVE-2020-37004HIGH8.2The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to...
CVE-2020-37001HIGH8.4Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attack...
CVE-2020-36999HIGH8.8Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipul...
CVE-2020-36995HIGH7.5Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application ...
CVE-2020-36973HIGH8.7PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename...
CVE-2020-36972HIGH7.5SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that a...
CVE-2020-36971HIGH8.4Nidesoft 3GP Video Converter 2.6.18 contains a local stack buffer overflow vulnerability in the license registration par...
CVE-2020-36970HIGH8.4PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system file...
CVE-2020-36969HIGH8.8M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions b...
CVE-2020-36968HIGH7.1M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password has...
CVE-2020-36965HIGH8.4docPrint Pro 8.0 contains a local buffer overflow vulnerability in the 'Add URL' input field that allows attackers to ex...
CVE-2020-36963HIGH8.7Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthentica...
CVE-2020-36945HIGH8.8WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to b...
CVE-2020-36943HIGH7.5aSc TimeTables 2021.6.2 contains a denial of service vulnerability that allows attackers to crash the application by ove...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now