2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10561 | CRITICAL | 9.8 | 2.5% | Jun 24, 2020 | An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web... |
| CVE-2020-14095 | CRITICAL | 9.8 | 2.3% | Jun 24, 2020 | In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web in... |
| CVE-2020-14094 | CRITICAL | 9.8 | 2.3% | Jun 24, 2020 | In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting ... |
| CVE-2020-13484 | CRITICAL | 9.8 | 2.0% | Jun 24, 2020 | Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview u... |
| CVE-2020-15007 | CRITICAL | 9.8 | 2.3% | Jun 24, 2020 | A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execut... |
| CVE-2020-10279 | CRITICAL | 9.8 | 1.0% | Jun 24, 2020 | MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop us... |
| CVE-2020-10276 | CRITICAL | 9.8 | 1.5% | Jun 24, 2020 | The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated progr... |
| CVE-2020-10275 | CRITICAL | 9.8 | 1.0% | Jun 24, 2020 | The access tokens for the REST API are directly derived from the publicly available default credentials for the web inte... |
| CVE-2020-10272 | CRITICAL | 9.8 | 2.5% | Jun 24, 2020 | MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra... |
| CVE-2020-10271 | CRITICAL | 9.8 | 1.8% | Jun 24, 2020 | MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra... |
| CVE-2020-10270 | CRITICAL | 9.8 | 1.7% | Jun 24, 2020 | Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to a... |
| CVE-2020-10269 | CRITICAL | 9.8 | 1.4% | Jun 24, 2020 | One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles com... |
| CVE-2020-9480 | CRITICAL | 9.8 | 29.2% | Jun 23, 2020 | In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (s... |
| CVE-2020-12021 | CRITICAL | 9 | 1.6% | Jun 23, 2020 | In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cros... |
| CVE-2020-14993 | CRITICAL | 9.8 | 5.3% | Jun 23, 2020 | A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attack... |
| CVE-2020-14938 | CRITICAL | 9.8 | 1.4% | Jun 23, 2020 | An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It ... |
| CVE-2020-5594 | CRITICAL | 9.8 | 1.3% | Jun 23, 2020 | Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows ... |
| CVE-2020-12782 | CRITICAL | 9.8 | 1.9% | Jun 23, 2020 | Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the ... |
| CVE-2020-14944 | CRITICAL | 9.8 | 6.3% | Jun 22, 2020 | Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all... |
| CVE-2020-14983 | CRITICAL | 9.8 | 2.2% | Jun 22, 2020 | The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading... |
| CVE-2020-12053 | CRITICAL | 9.8 | 0.7% | Jun 22, 2020 | In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoi... |
| CVE-2020-11989 | CRITICAL | 9.8 | 24.4% | Jun 22, 2020 | Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may caus... |
| CVE-2020-14972 | CRITICAL | 9.8 | 5.4% | Jun 22, 2020 | Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated... |
| CVE-2020-13159 | CRITICAL | 9.8 | 9.3% | Jun 22, 2020 | Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, ... |
| CVE-2020-4068 | CRITICAL | 9.8 | 1.3% | Jun 22, 2020 | In APNSwift 1.0.0, calling APNSwiftSigner.sign(digest:) is likely to result in a heap buffer overflow. This has been fix... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now