2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-10561CRITICAL9.8An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web...
CVE-2020-14095CRITICAL9.8In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web in...
CVE-2020-14094CRITICAL9.8In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting ...
CVE-2020-13484CRITICAL9.8Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview u...
CVE-2020-15007CRITICAL9.8A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execut...
CVE-2020-10279CRITICAL9.8MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop us...
CVE-2020-10276CRITICAL9.8The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated progr...
CVE-2020-10275CRITICAL9.8The access tokens for the REST API are directly derived from the publicly available default credentials for the web inte...
CVE-2020-10272CRITICAL9.8MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra...
CVE-2020-10271CRITICAL9.8MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra...
CVE-2020-10270CRITICAL9.8Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to a...
CVE-2020-10269CRITICAL9.8One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles com...
CVE-2020-9480CRITICAL9.8In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (s...
CVE-2020-12021CRITICAL9In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cros...
CVE-2020-14993CRITICAL9.8A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attack...
CVE-2020-14938CRITICAL9.8An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It ...
CVE-2020-5594CRITICAL9.8Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows ...
CVE-2020-12782CRITICAL9.8Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the ...
CVE-2020-14944CRITICAL9.8Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all...
CVE-2020-14983CRITICAL9.8The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading...
CVE-2020-12053CRITICAL9.8In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoi...
CVE-2020-11989CRITICAL9.8Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may caus...
CVE-2020-14972CRITICAL9.8Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated...
CVE-2020-13159CRITICAL9.8Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, ...
CVE-2020-4068CRITICAL9.8In APNSwift 1.0.0, calling APNSwiftSigner.sign(digest:) is likely to result in a heap buffer overflow. This has been fix...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now