2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-5681HIGH7.8Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlie...
CVE-2020-2504HIGH7.5If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP h...
CVE-2020-2499HIGH7.2A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerabilit...
CVE-2020-35668HIGH7.5RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquo...
CVE-2020-35666HIGH8.8Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/pac...
CVE-2020-35598HIGH7.5ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=....
CVE-2020-35370HIGH8.8A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically cra...
CVE-2020-35269HIGH8.8Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, li...
CVE-2020-27397HIGH8.8Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing...
CVE-2020-11719HIGH7.5An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encr...
CVE-2020-35587HIGH7.5In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files cont...
CVE-2020-29550HIGH7.5An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection o...
CVE-2020-11718HIGH7.4An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are ...
CVE-2020-35586HIGH7.5In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via th...
CVE-2020-35585HIGH7.5In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/in...
CVE-2020-35136HIGH7.2Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard...
CVE-2020-25198HIGH8.8The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protection...
CVE-2020-25194HIGH8.8The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, whi...
CVE-2020-25153HIGH7.5The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong...
CVE-2020-35657HIGH7.2Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme t...
CVE-2020-35656HIGH7.2Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?req...
CVE-2020-28641HIGH7.1In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the loca...
CVE-2020-27338HIGH7.1An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows a...
CVE-2020-27337HIGH7.3An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthe...
CVE-2020-24680HIGH7In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stor...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now