2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-28494HIGH8.6This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type ...
CVE-2020-24335HIGH7.5An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, ...
CVE-2020-25036HIGH8.8UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, an...
CVE-2020-25037HIGH8.2UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted ...
CVE-2020-20290HIGH7.5Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper ju...
CVE-2020-28426HIGH7.3All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.
CVE-2020-24271HIGH8.8A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/in...
CVE-2020-15834HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in ...
CVE-2020-15832HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented co...
CVE-2020-13860HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undo...
CVE-2020-13857HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sendin...
CVE-2020-13856HIGH7.5An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download t...
CVE-2020-14418HIGH7A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges t...
CVE-2020-35145HIGH7.8Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerab...
CVE-2020-29005HIGH7.5The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential ...
CVE-2020-29004HIGH8.8The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore ...
CVE-2020-28405HIGH8.8An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-28403HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an...
CVE-2020-28402HIGH8.8An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-35754HIGH7.2OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl...
CVE-2020-35517HIGH8.2A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a...
CVE-2020-4888HIGH8.8IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary com...
CVE-2020-13569HIGH8.8A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0...
CVE-2020-5626HIGH8.8Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbi...
CVE-2020-5427HIGH7.2In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now