2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-14936CRITICAL9.8Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. Functions parsing the OIDs in SNMP re...
CVE-2020-14935CRITICAL9.8Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function....
CVE-2020-14934CRITICAL9.8Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. The function parsing the received SNM...
CVE-2020-14937CRITICAL9.1Memory access out of buffer boundaries issues was discovered in Contiki-NG 4.4 through 4.5, in the SNMP BER encoder/deco...
CVE-2020-7708CRITICAL9.8The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via ...
CVE-2020-7707CRITICAL9.8The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
CVE-2020-7706CRITICAL9.8The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by...
CVE-2020-15152CRITICAL9.1ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv...
CVE-2020-1467CRITICAL10An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully ...
CVE-2020-7704CRITICAL9.8The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
CVE-2020-24208CRITICAL9.8A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to...
CVE-2020-9233CRITICAL9.1FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to dele...
CVE-2020-8212CRITICAL9.8Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix Xe...
CVE-2020-8211CRITICAL9.8Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix ...
CVE-2020-7703CRITICAL9.8All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.
CVE-2020-7702CRITICAL9.8All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.
CVE-2020-12606CRITICAL9.8An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webs...
CVE-2020-24361CRITICAL9.8SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
CVE-2020-17474CRITICAL9.8A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to...
CVE-2020-15692CRITICAL9.8In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument ca...
CVE-2020-15142CRITICAL9In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generat...
CVE-2020-15781CRITICAL9.6A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen...
CVE-2020-10055CRITICAL9.8A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (...
CVE-2020-7701CRITICAL9.8madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
CVE-2020-7700CRITICAL9.8All versions of phpjs are vulnerable to Prototype Pollution via parse_str.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now