2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-12873HIGH8.8An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a F...
CVE-2020-9050HIGH7.5Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenti...
CVE-2020-25171HIGH7.8The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may ...
CVE-2020-13549HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0...
CVE-2020-36249HIGH7.5The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares.
CVE-2020-10252HIGH8.3An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote pa...
CVE-2020-36247HIGH8.8Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.
CVE-2020-24908HIGH7.8Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDA...
CVE-2020-36246HIGH7.8Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.
CVE-2020-19513HIGH7.8Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a craf...
CVE-2020-36233HIGH7.8The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, ...
CVE-2020-28491HIGH7.5This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-...
CVE-2020-28496HIGH7.5This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require...
CVE-2020-29664HIGH7.8A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code...
CVE-2020-9306HIGH8.8Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi Connec...
CVE-2020-12878HIGH7.8Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlin...
CVE-2020-8625HIGH8.1BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a co...
CVE-2020-36245HIGH8.8GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent....
CVE-2020-13555HIGH8.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD...
CVE-2020-13553HIGH8.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD...
CVE-2020-13552HIGH8.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD...
CVE-2020-13551HIGH8.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD...
CVE-2020-13550HIGH7.7A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A spec...
CVE-2020-36003HIGH7.5The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads t...
CVE-2020-36002HIGH7.5Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtai...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now