2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-36569CRITICAL9.1Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 ...
CVE-2020-36566CRITICAL9.1Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten...
CVE-2020-36561CRITICAL9.1Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten...
CVE-2020-36560CRITICAL9.1Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten...
CVE-2020-24600CRITICAL9.8Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.
CVE-2020-11101CRITICAL9.8Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can ...
CVE-2020-36632CRITICAL9.8A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unfla...
CVE-2020-36631CRITICAL9.8A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerabi...
CVE-2020-36630CRITICAL9.8A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler...
CVE-2020-36628CRITICAL9.8A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the fi...
CVE-2020-36619CRITICAL9.8A vulnerability was found in multimon-ng. It has been rated as critical. This issue affects the function add_ch of the f...
CVE-2020-36618CRITICAL9.8A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file ...
CVE-2020-36617CRITICAL9.8A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is t...
CVE-2020-6627CRITICAL9.8The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS comman...
CVE-2020-23591CRITICAL9.8A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker t...
CVE-2020-23584CRITICAL9.8Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes ar...
CVE-2020-23583CRITICAL9.8OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary ...
CVE-2020-22820CRITICAL9.8MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
CVE-2020-22819CRITICAL9.8MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
CVE-2020-22818CRITICAL9.8MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
CVE-2020-21016CRITICAL9.8D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/S...
CVE-2020-8974CRITICAL9.1In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type ...
CVE-2020-14131CRITICAL9.8The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more out...
CVE-2020-14129CRITICAL9.8A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which...
CVE-2020-35674CRITICAL9.8BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordRe...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now