2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-13995CRITICAL9.8U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow i...
CVE-2020-15394CRITICAL9.8The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a ...
CVE-2020-26108CRITICAL9.8cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
CVE-2020-26105CRITICAL9.8In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
CVE-2020-26101CRITICAL9.8In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
CVE-2020-26100CRITICAL9.8chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
CVE-2020-26098CRITICAL9.8cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
CVE-2020-25749CRITICAL9.8The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow a...
CVE-2020-25747CRITICAL9.4The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote at...
CVE-2020-25223CRITICAL9.8A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 ...
CVE-2020-24594CRITICAL9.6Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due ...
CVE-2020-11805CRITICAL9.8Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
CVE-2020-15160CRITICAL9.8PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog ...
CVE-2020-15851CRITICAL9.8Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access une...
CVE-2020-3426CRITICAL9.1A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 S...
CVE-2020-12843CRITICAL9.8ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magi...
CVE-2020-12842CRITICAL9.8ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.
CVE-2020-12839CRITICAL9.8ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.
CVE-2020-12838CRITICAL9.8ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.
CVE-2020-13505CRITICAL9.8Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP w...
CVE-2020-13504CRITICAL9.8Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted...
CVE-2020-13501CRITICAL9.8An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1...
CVE-2020-13500CRITICAL9.8SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/...
CVE-2020-13499CRITICAL9.8An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1...
CVE-2020-16147CRITICAL9.8The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now