2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-7521CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC E...
CVE-2020-24786CRITICAL9.8An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number ...
CVE-2020-12645CRITICAL9.8OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed va...
CVE-2020-24115CRITICAL9.8In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
CVE-2020-25020CRITICAL9.8MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
CVE-2020-25016CRITICAL9.1A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arb...
CVE-2020-15165CRITICAL9.1Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampere...
CVE-2020-15164CRITICAL10in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username wit...
CVE-2020-5624CRITICAL9.8SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands vi...
CVE-2020-24715CRITICAL9.8The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code...
CVE-2020-24714CRITICAL9.8The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary...
CVE-2020-24203CRITICAL9.8Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects Worl...
CVE-2020-24202CRITICAL9.8File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regul...
CVE-2020-23979CRITICAL9.813enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
CVE-2020-23978CRITICAL9.8SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
CVE-2020-23976CRITICAL9.8Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
CVE-2020-23973CRITICAL9.8KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
CVE-2020-23980CRITICAL9.8DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login pa...
CVE-2020-15158CRITICAL9.8In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer...
CVE-2020-3446CRITICAL9.8A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Softwar...
CVE-2020-24007CRITICAL9.8Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerabili...
CVE-2020-14498CRITICAL10HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which ma...
CVE-2020-24653CRITICAL9.8secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN...
CVE-2020-15639CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso...
CVE-2020-16245CRITICAL9.8Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now