2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-9297CRITICAL9.8Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint valida...
CVE-2020-11546CRITICAL9.8SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing...
CVE-2020-7593CRITICAL9.8A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLU...
CVE-2020-1948CRITICAL9.8This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unr...
CVE-2020-13753CRITICAL10The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER an...
CVE-2020-11956CRITICAL9.8An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is ...
CVE-2020-10042CRITICAL9.8A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions...
CVE-2020-10038CRITICAL9.8A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions...
CVE-2020-6287CRITICAL10SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c...
CVE-2020-13926CRITICAL9.8Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is f...
CVE-2020-13925CRITICAL9.8Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then exe...
CVE-2020-11951CRITICAL9.8An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is ...
CVE-2020-10988CRITICAL9.8A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated...
CVE-2020-10987CRITICAL9.8The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary s...
CVE-2020-11749CRITICAL9Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator ...
CVE-2020-15504CRITICAL9.8A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially...
CVE-2020-8186CRITICAL9.8A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pas...
CVE-2020-7815CRITICAL9.8XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by settin...
CVE-2020-7814CRITICAL9.8RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and ex...
CVE-2020-7692CRITICAL9.1PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the a...
CVE-2020-7458CRITICAL9.8In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-c...
CVE-2020-11849CRITICAL9.8Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prio...
CVE-2020-3931CRITICAL9.8Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute ar...
CVE-2020-8521CRITICAL9.8SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with a...
CVE-2020-8520CRITICAL9.8SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with aja...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now