2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12873 | HIGH | 8.8 | 1.6% | Feb 19, 2021 | An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a F... |
| CVE-2020-9050 | HIGH | 7.5 | 2.1% | Feb 19, 2021 | Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenti... |
| CVE-2020-25171 | HIGH | 7.8 | 1.0% | Feb 19, 2021 | The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may ... |
| CVE-2020-13549 | HIGH | 7.8 | 0.5% | Feb 19, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0... |
| CVE-2020-36249 | HIGH | 7.5 | 0.8% | Feb 19, 2021 | The File Firewall before 2.8.0 for ownCloud Server does not properly enforce file-type restrictions for public shares. |
| CVE-2020-10252 | HIGH | 8.3 | 1.2% | Feb 19, 2021 | An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote pa... |
| CVE-2020-36247 | HIGH | 8.8 | 0.4% | Feb 19, 2021 | Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF. |
| CVE-2020-24908 | HIGH | 7.8 | 0.3% | Feb 19, 2021 | Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDA... |
| CVE-2020-36246 | HIGH | 7.8 | 0.5% | Feb 19, 2021 | Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link. |
| CVE-2020-19513 | HIGH | 7.8 | 0.5% | Feb 19, 2021 | Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a craf... |
| CVE-2020-36233 | HIGH | 7.8 | 0.3% | Feb 18, 2021 | The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, ... |
| CVE-2020-28491 | HIGH | 7.5 | 3.1% | Feb 18, 2021 | This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-... |
| CVE-2020-28496 | HIGH | 7.5 | 2.5% | Feb 18, 2021 | This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require... |
| CVE-2020-29664 | HIGH | 7.8 | 1.5% | Feb 18, 2021 | A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code... |
| CVE-2020-9306 | HIGH | 8.8 | 1.2% | Feb 18, 2021 | Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi Connec... |
| CVE-2020-12878 | HIGH | 7.8 | 0.5% | Feb 18, 2021 | Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlin... |
| CVE-2020-8625 | HIGH | 8.1 | 64.2% | Feb 17, 2021 | BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a co... |
| CVE-2020-36245 | HIGH | 8.8 | 1.5% | Feb 17, 2021 | GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent.... |
| CVE-2020-13555 | HIGH | 8.8 | 0.5% | Feb 17, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD... |
| CVE-2020-13553 | HIGH | 8.8 | 0.5% | Feb 17, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD... |
| CVE-2020-13552 | HIGH | 8.8 | 0.5% | Feb 17, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD... |
| CVE-2020-13551 | HIGH | 8.8 | 0.5% | Feb 17, 2021 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD... |
| CVE-2020-13550 | HIGH | 7.7 | 3.5% | Feb 17, 2021 | A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A spec... |
| CVE-2020-36003 | HIGH | 7.5 | 1.5% | Feb 17, 2021 | The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads t... |
| CVE-2020-36002 | HIGH | 7.5 | 1.6% | Feb 17, 2021 | Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtai... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now