2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28494 | HIGH | 8.6 | 1.7% | Feb 2, 2021 | This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type ... |
| CVE-2020-24335 | HIGH | 7.5 | 3.0% | Feb 2, 2021 | An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, ... |
| CVE-2020-25036 | HIGH | 8.8 | 2.0% | Feb 2, 2021 | UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, an... |
| CVE-2020-25037 | HIGH | 8.2 | 0.5% | Feb 2, 2021 | UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted ... |
| CVE-2020-20290 | HIGH | 7.5 | 1.3% | Feb 1, 2021 | Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper ju... |
| CVE-2020-28426 | HIGH | 7.3 | 1.9% | Feb 1, 2021 | All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId. |
| CVE-2020-24271 | HIGH | 8.8 | 0.6% | Feb 1, 2021 | A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/in... |
| CVE-2020-15834 | HIGH | 7.5 | 1.1% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in ... |
| CVE-2020-15832 | HIGH | 7.5 | 1.1% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The poof.cgi script contains undocumented co... |
| CVE-2020-13860 | HIGH | 7.5 | 1.1% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undo... |
| CVE-2020-13857 | HIGH | 7.5 | 1.1% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sendin... |
| CVE-2020-13856 | HIGH | 7.5 | 1.2% | Feb 1, 2021 | An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download t... |
| CVE-2020-14418 | HIGH | 7 | 0.3% | Jan 30, 2021 | A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges t... |
| CVE-2020-35145 | HIGH | 7.8 | 0.6% | Jan 29, 2021 | Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerab... |
| CVE-2020-29005 | HIGH | 7.5 | 0.7% | Jan 29, 2021 | The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential ... |
| CVE-2020-29004 | HIGH | 8.8 | 0.7% | Jan 29, 2021 | The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore ... |
| CVE-2020-28405 | HIGH | 8.8 | 1.6% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-28403 | HIGH | 8.8 | 0.7% | Jan 29, 2021 | A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an... |
| CVE-2020-28402 | HIGH | 8.8 | 1.4% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-35754 | HIGH | 7.2 | 10.5% | Jan 28, 2021 | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl... |
| CVE-2020-35517 | HIGH | 8.2 | 0.5% | Jan 28, 2021 | A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a... |
| CVE-2020-4888 | HIGH | 8.8 | 62.0% | Jan 28, 2021 | IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary com... |
| CVE-2020-13569 | HIGH | 8.8 | 3.0% | Jan 28, 2021 | A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0... |
| CVE-2020-5626 | HIGH | 8.8 | 2.2% | Jan 28, 2021 | Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbi... |
| CVE-2020-5427 | HIGH | 7.2 | 1.1% | Jan 27, 2021 | In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now