2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-37125CRITICAL9.8Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to e...
CVE-2020-37124CRITICAL9.8B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Str...
CVE-2020-37123CRITICAL9.8Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the pin...
CVE-2020-37121MEDIUM6.7CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriti...
CVE-2020-37120CRITICAL9.8Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attacker...
CVE-2020-37119CRITICAL9.8Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to ex...
CVE-2020-37118MEDIUM5.1P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform admi...
CVE-2020-37117HIGH8.8jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated adm...
CVE-2020-37151HIGH7.5phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter th...
CVE-2020-37087MEDIUM5.1Easy Transfer Wifi Transfer v1.7 for iOS contains a persistent cross-site scripting vulnerability that allows remote att...
CVE-2020-37084HIGH7.2School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitr...
CVE-2020-37097HIGH8.7Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details ...
CVE-2020-37096MEDIUM4.3Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface....
CVE-2020-37094HIGH8.6EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to...
CVE-2020-37093HIGH8.7Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve W...
CVE-2020-37092CRITICAL9.3Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to acc...
CVE-2020-37091MEDIUM5.3Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administr...
CVE-2020-37090CRITICAL9.8School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messag...
CVE-2020-37089CRITICAL9.8School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to mani...
CVE-2020-37088HIGH8.7School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary file...
CVE-2020-37086MEDIUM6.9Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to ac...
CVE-2020-37085HIGH8.7VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by send...
CVE-2020-37083HIGH8.8PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipula...
CVE-2020-37082HIGH7.5webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database ba...
CVE-2020-37081HIGH7.1Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calend...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now