2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7521 | CRITICAL | 9.8 | 1.7% | Aug 31, 2020 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC E... |
| CVE-2020-24786 | CRITICAL | 9.8 | 12.8% | Aug 31, 2020 | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number ... |
| CVE-2020-12645 | CRITICAL | 9.8 | 1.1% | Aug 31, 2020 | OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed va... |
| CVE-2020-24115 | CRITICAL | 9.8 | 2.0% | Aug 31, 2020 | In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access. |
| CVE-2020-25020 | CRITICAL | 9.8 | 2.6% | Aug 29, 2020 | MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. |
| CVE-2020-25016 | CRITICAL | 9.1 | 1.6% | Aug 29, 2020 | A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arb... |
| CVE-2020-15165 | CRITICAL | 9.1 | 1.3% | Aug 28, 2020 | Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampere... |
| CVE-2020-15164 | CRITICAL | 10 | 1.2% | Aug 28, 2020 | in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username wit... |
| CVE-2020-5624 | CRITICAL | 9.8 | 1.4% | Aug 28, 2020 | SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2020-24715 | CRITICAL | 9.8 | 0.8% | Aug 27, 2020 | The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code... |
| CVE-2020-24714 | CRITICAL | 9.8 | 1.0% | Aug 27, 2020 | The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary... |
| CVE-2020-24203 | CRITICAL | 9.8 | 3.7% | Aug 27, 2020 | Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects Worl... |
| CVE-2020-24202 | CRITICAL | 9.8 | 2.9% | Aug 27, 2020 | File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regul... |
| CVE-2020-23979 | CRITICAL | 9.8 | 1.9% | Aug 27, 2020 | 13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter. |
| CVE-2020-23978 | CRITICAL | 9.8 | 2.1% | Aug 27, 2020 | SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php" |
| CVE-2020-23976 | CRITICAL | 9.8 | 2.2% | Aug 27, 2020 | Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter. |
| CVE-2020-23973 | CRITICAL | 9.8 | 1.6% | Aug 27, 2020 | KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter. |
| CVE-2020-23980 | CRITICAL | 9.8 | 2.2% | Aug 27, 2020 | DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login pa... |
| CVE-2020-15158 | CRITICAL | 9.8 | 2.0% | Aug 26, 2020 | In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer... |
| CVE-2020-3446 | CRITICAL | 9.8 | 1.4% | Aug 26, 2020 | A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Softwar... |
| CVE-2020-24007 | CRITICAL | 9.8 | 1.6% | Aug 26, 2020 | Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerabili... |
| CVE-2020-14498 | CRITICAL | 10 | 2.9% | Aug 26, 2020 | HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which ma... |
| CVE-2020-24653 | CRITICAL | 9.8 | 1.2% | Aug 26, 2020 | secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN... |
| CVE-2020-15639 | CRITICAL | 9.8 | 11.5% | Aug 25, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso... |
| CVE-2020-16245 | CRITICAL | 9.8 | 7.7% | Aug 25, 2020 | Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now