2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8519 | CRITICAL | 9.8 | 1.4% | Jul 7, 2020 | SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php... |
| CVE-2020-12821 | CRITICAL | 9.8 | 1.9% | Jul 7, 2020 | Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack. |
| CVE-2020-15350 | CRITICAL | 9.8 | 1.5% | Jul 7, 2020 | RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer es... |
| CVE-2020-15367 | CRITICAL | 9.8 | 2.0% | Jul 7, 2020 | Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit th... |
| CVE-2020-5599 | CRITICAL | 9.8 | 3.5% | Jul 7, 2020 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta... |
| CVE-2020-5595 | CRITICAL | 9.8 | 2.5% | Jul 7, 2020 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta... |
| CVE-2020-15506 | CRITICAL | 9.8 | 2.8% | Jul 7, 2020 | An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,... |
| CVE-2020-15505 | CRITICAL | 9.8 | 99.7% | Jul 7, 2020 | A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, ... |
| CVE-2020-4077 | CRITICAL | 9.9 | 1.0% | Jul 7, 2020 | In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the mai... |
| CVE-2020-4076 | CRITICAL | 9 | 0.4% | Jul 7, 2020 | In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the mai... |
| CVE-2020-15543 | CRITICAL | 9.8 | 1.6% | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path. |
| CVE-2020-15542 | CRITICAL | 9.8 | 1.6% | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command. |
| CVE-2020-15541 | CRITICAL | 9.8 | 7.0% | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution. |
| CVE-2020-15540 | CRITICAL | 9.8 | 1.8% | Jul 5, 2020 | We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page. |
| CVE-2020-15539 | CRITICAL | 9.8 | 1.8% | Jul 5, 2020 | SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field. |
| CVE-2020-10282 | CRITICAL | 9.8 | 1.7% | Jul 3, 2020 | The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization... |
| CVE-2020-14172 | CRITICAL | 9.8 | 2.5% | Jul 3, 2020 | This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templ... |
| CVE-2020-4074 | CRITICAL | 9.8 | 1.8% | Jul 2, 2020 | In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is... |
| CVE-2020-14092 | CRITICAL | 9.8 | 94.5% | Jul 2, 2020 | The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection. |
| CVE-2020-7821 | CRITICAL | 9.8 | 1.6% | Jul 2, 2020 | Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to ... |
| CVE-2020-7820 | CRITICAL | 9.8 | 1.6% | Jul 2, 2020 | Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to ... |
| CVE-2020-3297 | CRITICAL | 9.8 | 3.0% | Jul 2, 2020 | A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches cou... |
| CVE-2020-15490 | CRITICAL | 9.8 | 3.7% | Jul 1, 2020 | An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exi... |
| CVE-2020-15489 | CRITICAL | 9.8 | 3.7% | Jul 1, 2020 | An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulne... |
| CVE-2020-14057 | CRITICAL | 9.8 | 2.6% | Jul 1, 2020 | Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now