2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-8519CRITICAL9.8SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php...
CVE-2020-12821CRITICAL9.8Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
CVE-2020-15350CRITICAL9.8RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer es...
CVE-2020-15367CRITICAL9.8Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit th...
CVE-2020-5599CRITICAL9.8TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta...
CVE-2020-5595CRITICAL9.8TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta...
CVE-2020-15506CRITICAL9.8An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,...
CVE-2020-15505CRITICAL9.8A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, ...
CVE-2020-4077CRITICAL9.9In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the mai...
CVE-2020-4076CRITICAL9In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the mai...
CVE-2020-15543CRITICAL9.8SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
CVE-2020-15542CRITICAL9.8SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
CVE-2020-15541CRITICAL9.8SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
CVE-2020-15540CRITICAL9.8We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.
CVE-2020-15539CRITICAL9.8SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.
CVE-2020-10282CRITICAL9.8The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization...
CVE-2020-14172CRITICAL9.8This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templ...
CVE-2020-4074CRITICAL9.8In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is...
CVE-2020-14092CRITICAL9.8The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
CVE-2020-7821CRITICAL9.8Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to ...
CVE-2020-7820CRITICAL9.8Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to ...
CVE-2020-3297CRITICAL9.8A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches cou...
CVE-2020-15490CRITICAL9.8An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exi...
CVE-2020-15489CRITICAL9.8An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulne...
CVE-2020-14057CRITICAL9.8Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now