2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-35558HIGH7.5An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2...
CVE-2020-35734HIGH7.2Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution)...
CVE-2020-29143HIGH7.2A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authentica...
CVE-2020-29140HIGH7.2A SQL injection vulnerability in interface/reports/immunization_report.php in OpenEMR before 5.0.2.5 allows a remote aut...
CVE-2020-29139HIGH7.2A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0...
CVE-2020-29142HIGH7.2A SQL injection vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.5 allows a remote authe...
CVE-2020-28337HIGH7.2A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to g...
CVE-2020-24899HIGH8.8Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional ...
CVE-2020-22427HIGH7.2NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject...
CVE-2020-22425HIGH8.8Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional...
CVE-2020-35512HIGH7.8A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1...
CVE-2020-29031HIGH8.1An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated ...
CVE-2020-4955HIGH8IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system,...
CVE-2020-13949HIGH7.5In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory a...
CVE-2020-27869HIGH8.8This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Perfor...
CVE-2020-27866HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020...
CVE-2020-27865HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1...
CVE-2020-27864HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1...
CVE-2020-27862HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2...
CVE-2020-27861HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi...
CVE-2020-27860HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35...
CVE-2020-35498HIGH7.5A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a mal...
CVE-2020-25493HIGH7.5Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the netw...
CVE-2020-27874HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18....
CVE-2020-27871HIGH7.2This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platf...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now