2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5681 | HIGH | 7.8 | 0.9% | Dec 24, 2020 | Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlie... |
| CVE-2020-2504 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP h... |
| CVE-2020-2499 | HIGH | 7.2 | 1.4% | Dec 24, 2020 | A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerabilit... |
| CVE-2020-35668 | HIGH | 7.5 | 1.6% | Dec 23, 2020 | RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquo... |
| CVE-2020-35666 | HIGH | 8.8 | 1.1% | Dec 23, 2020 | Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/pac... |
| CVE-2020-35598 | HIGH | 7.5 | 21.0% | Dec 23, 2020 | ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=.... |
| CVE-2020-35370 | HIGH | 8.8 | 7.5% | Dec 23, 2020 | A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically cra... |
| CVE-2020-35269 | HIGH | 8.8 | 2.3% | Dec 23, 2020 | Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, li... |
| CVE-2020-27397 | HIGH | 8.8 | 2.6% | Dec 23, 2020 | Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing... |
| CVE-2020-11719 | HIGH | 7.5 | 1.0% | Dec 23, 2020 | An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encr... |
| CVE-2020-35587 | HIGH | 7.5 | 1.5% | Dec 23, 2020 | In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files cont... |
| CVE-2020-29550 | HIGH | 7.5 | 1.4% | Dec 23, 2020 | An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection o... |
| CVE-2020-11718 | HIGH | 7.4 | 0.8% | Dec 23, 2020 | An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are ... |
| CVE-2020-35586 | HIGH | 7.5 | 1.4% | Dec 23, 2020 | In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via th... |
| CVE-2020-35585 | HIGH | 7.5 | 1.4% | Dec 23, 2020 | In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/in... |
| CVE-2020-35136 | HIGH | 7.2 | 6.4% | Dec 23, 2020 | Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard... |
| CVE-2020-25198 | HIGH | 8.8 | 1.1% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protection... |
| CVE-2020-25194 | HIGH | 8.8 | 1.0% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, whi... |
| CVE-2020-25153 | HIGH | 7.5 | 1.2% | Dec 23, 2020 | The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong... |
| CVE-2020-35657 | HIGH | 7.2 | 2.4% | Dec 23, 2020 | Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme t... |
| CVE-2020-35656 | HIGH | 7.2 | 2.4% | Dec 23, 2020 | Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?req... |
| CVE-2020-28641 | HIGH | 7.1 | 0.8% | Dec 22, 2020 | In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the loca... |
| CVE-2020-27338 | HIGH | 7.1 | 0.8% | Dec 22, 2020 | An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows a... |
| CVE-2020-27337 | HIGH | 7.3 | 1.5% | Dec 22, 2020 | An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthe... |
| CVE-2020-24680 | HIGH | 7 | 0.3% | Dec 22, 2020 | In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stor... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now