2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-1891CRITICAL9.8A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android ...
CVE-2020-1889CRITICAL10A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in...
CVE-2020-24193CRITICAL9.8A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execu...
CVE-2020-24876CRITICAL9.8Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which m...
CVE-2020-25105CRITICAL9.8eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilit...
CVE-2020-4693CRITICAL9.8IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to exe...
CVE-2020-24030CRITICAL9.8ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access...
CVE-2020-24029CRITICAL9.8Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can b...
CVE-2020-13802CRITICAL9.8Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specificat...
CVE-2020-24355CRITICAL9.8Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insec...
CVE-2020-6874CRITICAL9.1A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so r...
CVE-2020-6151CRITICAL9.8A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19....
CVE-2020-6144CRITICAL9.8A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable wh...
CVE-2020-6143CRITICAL9.8A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable wh...
CVE-2020-6142CRITICAL9.8A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. A specially crafted ...
CVE-2020-6140CRITICAL9.8SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email para...
CVE-2020-6139CRITICAL9.8SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The username_stf_email para...
CVE-2020-6138CRITICAL9.8SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The uname parameter in the ...
CVE-2020-6137CRITICAL9.8SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email para...
CVE-2020-5777CRITICAL9.8MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in t...
CVE-2020-25069CRITICAL9.8USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view.
CVE-2020-16210CRITICAL9The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute ar...
CVE-2020-16206CRITICAL9The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbit...
CVE-2020-16204CRITICAL9.8The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to ...
CVE-2020-6141CRITICAL9.8An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted H...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now