2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-12471CRITICAL9.8MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGal...
CVE-2020-11020CRITICAL9.8Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication ...
CVE-2020-3955CRITICAL9.3ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize s...
CVE-2020-8481CRITICAL9.8For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions...
CVE-2020-8479CRITICAL9.8For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions ...
CVE-2020-12443CRITICAL9.8BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value ca...
CVE-2020-7452CRITICAL9.1In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE...
CVE-2020-12442CRITICAL9.8Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.
CVE-2020-12429CRITICAL9.8Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and aut...
CVE-2020-1745CRITICAL9.8A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in U...
CVE-2020-12284CRITICAL9.8cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MA...
CVE-2020-7640CRITICAL9.8pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be con...
CVE-2020-7609CRITICAL9.8node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fr...
CVE-2020-9294CRITICAL9.8An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an...
CVE-2020-1952CRITICAL9.8An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed ...
CVE-2020-12279CRITICAL9.8An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that...
CVE-2020-12278CRITICAL9.8An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exi...
CVE-2020-9068CRITICAL9.8Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200...
CVE-2020-12133CRITICAL9.8The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of...
CVE-2020-11817CRITICAL9.8In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As...
CVE-2020-12274CRITICAL9.8In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on ...
CVE-2020-12271CRITICAL9.8A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as e...
CVE-2020-12268CRITICAL9.8jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
CVE-2020-12267CRITICAL9.8setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
CVE-2020-12265CRITICAL9.8The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now