2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14056 | CRITICAL | 9.8 | 1.3% | Jul 1, 2020 | Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of th... |
| CVE-2020-13619 | CRITICAL | 9.8 | 2.9% | Jul 1, 2020 | php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution. |
| CVE-2020-5902 | CRITICAL | 9.8 | 100.0% | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic ... |
| CVE-2020-5901 | CRITICAL | 9.6 | 1.5% | Jul 1, 2020 | In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. ... |
| CVE-2020-13382 | CRITICAL | 9.1 | 52.8% | Jul 1, 2020 | openSIS through 7.4 has Incorrect Access Control. |
| CVE-2020-13381 | CRITICAL | 9.8 | 59.0% | Jul 1, 2020 | openSIS through 7.4 allows SQL Injection. |
| CVE-2020-13380 | CRITICAL | 9.8 | 2.4% | Jul 1, 2020 | openSIS before 7.4 allows SQL Injection. |
| CVE-2020-15475 | CRITICAL | 9.8 | 1.2% | Jul 1, 2020 | In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-aft... |
| CVE-2020-15474 | CRITICAL | 9.8 | 1.2% | Jul 1, 2020 | In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c. |
| CVE-2020-15473 | CRITICAL | 9.1 | 1.3% | Jul 1, 2020 | In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/... |
| CVE-2020-15472 | CRITICAL | 9.1 | 1.5% | Jul 1, 2020 | In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/proto... |
| CVE-2020-15471 | CRITICAL | 9.1 | 1.3% | Jul 1, 2020 | In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_in... |
| CVE-2020-15468 | CRITICAL | 9.8 | 2.7% | Jul 1, 2020 | Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter. |
| CVE-2020-9413 | CRITICAL | 9.6 | 1.3% | Jun 30, 2020 | The MFT Browser file transfer client and MFT Browser admin client components of TIBCO Software Inc.'s TIBCO Managed File... |
| CVE-2020-15084 | CRITICAL | 9.1 | 1.1% | Jun 30, 2020 | In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration i... |
| CVE-2020-15415 | CRITICAL | 9.8 | 84.6% | Jun 30, 2020 | On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote... |
| CVE-2020-15411 | CRITICAL | 9.8 | 1.4% | Jun 30, 2020 | An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the atta... |
| CVE-2020-15069 | CRITICAL | 9.8 | 10.7% | Jun 29, 2020 | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks f... |
| CVE-2020-15362 | CRITICAL | 9.8 | 2.5% | Jun 29, 2020 | wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite th... |
| CVE-2020-14072 | CRITICAL | 9.8 | 3.4% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin sc... |
| CVE-2020-14070 | CRITICAL | 9.8 | 1.8% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessabl... |
| CVE-2020-14068 | CRITICAL | 9.8 | 1.1% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and ga... |
| CVE-2020-15324 | CRITICAL | 9.8 | 1.2% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that ... |
| CVE-2020-15323 | CRITICAL | 9.8 | 1.2% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials. |
| CVE-2020-15322 | CRITICAL | 9.8 | 1.2% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now