2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-14056CRITICAL9.8Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of th...
CVE-2020-13619CRITICAL9.8php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
CVE-2020-5902CRITICAL9.8In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic ...
CVE-2020-5901CRITICAL9.6In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. ...
CVE-2020-13382CRITICAL9.1openSIS through 7.4 has Incorrect Access Control.
CVE-2020-13381CRITICAL9.8openSIS through 7.4 allows SQL Injection.
CVE-2020-13380CRITICAL9.8openSIS before 7.4 allows SQL Injection.
CVE-2020-15475CRITICAL9.8In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-aft...
CVE-2020-15474CRITICAL9.8In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
CVE-2020-15473CRITICAL9.1In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/...
CVE-2020-15472CRITICAL9.1In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/proto...
CVE-2020-15471CRITICAL9.1In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_in...
CVE-2020-15468CRITICAL9.8Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
CVE-2020-9413CRITICAL9.6The MFT Browser file transfer client and MFT Browser admin client components of TIBCO Software Inc.'s TIBCO Managed File...
CVE-2020-15084CRITICAL9.1In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration i...
CVE-2020-15415CRITICAL9.8On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote...
CVE-2020-15411CRITICAL9.8An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the atta...
CVE-2020-15069CRITICAL9.8Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks f...
CVE-2020-15362CRITICAL9.8wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite th...
CVE-2020-14072CRITICAL9.8An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin sc...
CVE-2020-14070CRITICAL9.8An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessabl...
CVE-2020-14068CRITICAL9.8An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and ga...
CVE-2020-15324CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that ...
CVE-2020-15323CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
CVE-2020-15322CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now