2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-14524CRITICAL9.8Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerab...
CVE-2020-14510CRITICAL9.8GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unpriv...
CVE-2020-14508CRITICAL9.8GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attack...
CVE-2020-14500CRITICAL9.8Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.
CVE-2020-7376CRITICAL9.8The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability...
CVE-2020-6637CRITICAL9.8openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
CVE-2020-24186CRITICAL10A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo...
CVE-2020-8234CRITICAL9.8A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cooki...
CVE-2020-24590CRITICAL9.1The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
CVE-2020-24589CRITICAL9.1The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection...
CVE-2020-15140CRITICAL9.6In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Di...
CVE-2020-24055CRITICAL9.8Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service im...
CVE-2020-24054CRITICAL9.8The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that...
CVE-2020-24052CRITICAL9.1Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unaut...
CVE-2020-24051CRITICAL9.8The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol,...
CVE-2020-7710CRITICAL9.8This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host m...
CVE-2020-16279CRITICAL9.8The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplie...
CVE-2020-23935CRITICAL9.8Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (...
CVE-2020-23936CRITICAL9.8PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Passwo...
CVE-2020-10283CRITICAL9.8The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to...
CVE-2020-17456CRITICAL9.8SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa...
CVE-2020-15636CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, ...
CVE-2020-15149CRITICAL9.9NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to ch...
CVE-2020-24032CRITICAL9.8tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharac...
CVE-2020-15865CRITICAL9.8A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now