2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13995 | CRITICAL | 9.8 | 2.7% | Sep 25, 2020 | U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow i... |
| CVE-2020-15394 | CRITICAL | 9.8 | 7.9% | Sep 25, 2020 | The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a ... |
| CVE-2020-26108 | CRITICAL | 9.8 | 2.5% | Sep 25, 2020 | cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488). |
| CVE-2020-26105 | CRITICAL | 9.8 | 1.4% | Sep 25, 2020 | In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554). |
| CVE-2020-26101 | CRITICAL | 9.8 | 1.4% | Sep 25, 2020 | In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549). |
| CVE-2020-26100 | CRITICAL | 9.8 | 1.6% | Sep 25, 2020 | chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497). |
| CVE-2020-26098 | CRITICAL | 9.8 | 3.0% | Sep 25, 2020 | cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). |
| CVE-2020-25749 | CRITICAL | 9.8 | 3.1% | Sep 25, 2020 | The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow a... |
| CVE-2020-25747 | CRITICAL | 9.4 | 1.8% | Sep 25, 2020 | The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote at... |
| CVE-2020-25223 | CRITICAL | 9.8 | 96.7% | Sep 25, 2020 | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 ... |
| CVE-2020-24594 | CRITICAL | 9.6 | 1.7% | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due ... |
| CVE-2020-11805 | CRITICAL | 9.8 | 1.4% | Sep 25, 2020 | Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN. |
| CVE-2020-15160 | CRITICAL | 9.8 | 10.8% | Sep 24, 2020 | PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog ... |
| CVE-2020-15851 | CRITICAL | 9.8 | 1.5% | Sep 24, 2020 | Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access une... |
| CVE-2020-3426 | CRITICAL | 9.1 | 2.2% | Sep 24, 2020 | A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 S... |
| CVE-2020-12843 | CRITICAL | 9.8 | 1.3% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magi... |
| CVE-2020-12842 | CRITICAL | 9.8 | 1.5% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php. |
| CVE-2020-12839 | CRITICAL | 9.8 | 1.5% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php. |
| CVE-2020-12838 | CRITICAL | 9.8 | 1.5% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php. |
| CVE-2020-13505 | CRITICAL | 9.8 | 1.2% | Sep 24, 2020 | Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP w... |
| CVE-2020-13504 | CRITICAL | 9.8 | 1.2% | Sep 24, 2020 | Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted... |
| CVE-2020-13501 | CRITICAL | 9.8 | 2.9% | Sep 24, 2020 | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1... |
| CVE-2020-13500 | CRITICAL | 9.8 | 2.9% | Sep 24, 2020 | SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/... |
| CVE-2020-13499 | CRITICAL | 9.8 | 2.9% | Sep 24, 2020 | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1... |
| CVE-2020-16147 | CRITICAL | 9.8 | 2.0% | Sep 24, 2020 | The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now