2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-27602CRITICAL9.8BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authTo...
CVE-2020-15347CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
CVE-2020-15332CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
CVE-2020-15331CRITICAL9.8Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
CVE-2020-19586CRITICAL9Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via ...
CVE-2020-21516CRITICAL9.8There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to exe...
CVE-2020-22669CRITICAL9.8Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can ...
CVE-2020-35527CRITICAL9.8In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
CVE-2020-27836CRITICAL9.8A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source r...
CVE-2020-27794CRITICAL9.1A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modificati...
CVE-2020-36599CRITICAL9.8lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
CVE-2020-21642CRITICAL9.8Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus befo...
CVE-2020-7795CRITICAL9.8The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
CVE-2020-28453CRITICAL9.8This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
CVE-2020-28451CRITICAL9.8This affects the package image-tiler before 2.0.2.
CVE-2020-28437CRITICAL9.8This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index...
CVE-2020-28434CRITICAL9.8This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
CVE-2020-28433CRITICAL9.8This affects all versions of package node-latex-pdf.
CVE-2020-28425CRITICAL9.8This affects all versions of package curljs.
CVE-2020-28424CRITICAL9.8This affects all versions of package s3-kilatstorage.
CVE-2020-28423CRITICAL9.8This affects all versions of package monorepo-build.
CVE-2020-7678CRITICAL9.8This affects all versions of package node-import. The "params" argument of module function can be controlled by users wi...
CVE-2020-7677CRITICAL9.8This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users with...
CVE-2020-28471CRITICAL9.8This affects the package properties-reader before 2.2.0.
CVE-2020-28462CRITICAL9.8This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that pars...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now