2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9269HIGH7.2SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as...
CVE-2020-9268HIGH7.5SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_creat...
CVE-2020-9267MEDIUM6.5SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
CVE-2020-9266MEDIUM6.5SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xaja...
CVE-2020-9265HIGH8.2phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demon...
CVE-2020-7450CRITICAL9.8In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-S...
CVE-2020-9264MEDIUM5.5ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a Z...
CVE-2020-8998Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-6845MEDIUM6.1An issue was discovered in TopManage OLK 2020. As there is no ReadOnly on the Session cookie, the user and admin account...
CVE-2020-6844HIGH8.8In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts...
CVE-2020-5530HIGH8.8Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers ...
CVE-2020-8012CRITICAL9.8CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi...
CVE-2020-8011HIGH7.5CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a null pointer dereference ...
CVE-2020-8010CRITICAL9.8CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vu...
CVE-2020-1842MEDIUM6.8Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X versio...
CVE-2020-1855MEDIUM6.1Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3...
CVE-2020-1843MEDIUM6.8Huawei HEGE-560 version 1.0.1.20(SP2), OSCA-550 version 1.0.0.71(SP1), OSCA-550A version 1.0.0.71(SP1), OSCA-550AX versi...
CVE-2020-1812HIGH7.8HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability....
CVE-2020-1791LOW2.4HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.185(C00E74R3P8) have an improper authorization vulnerabilit...
CVE-2020-1790HIGH8.8GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command usin...
CVE-2020-1789MEDIUM6.8Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentic...
CVE-2020-1872MEDIUM4.6Huawei smart phones P10 Plus with versions earlier than 9.1.0.201(C01E75R1P12T8), earlier than 9.1.0.252(C185E2R1P9T8), ...
CVE-2020-1814MEDIUM5.3Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001...
CVE-2020-1882MEDIUM4.6Huawei mobile phones Ever-L29B versions earlier than 10.0.0.180(C185E6R3P3), earlier than 10.0.0.180(C432E6R1P7), earlie...
CVE-2020-1830MEDIUM5.3Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now