2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-2801CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th...
CVE-2020-2791CRITICAL9.8Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported ve...
CVE-2020-2733CRITICAL9.8Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics)...
CVE-2020-10511CRITICAL9.8HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure ...
CVE-2020-10507CRITICAL9.8The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted ...
CVE-2020-10505CRITICAL9.8The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection...
CVE-2020-6195CRITICAL9.8SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, l...
CVE-2020-6238CRITICAL9.3SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xy...
CVE-2020-10383CRITICAL9.8An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. The...
CVE-2020-11673CRITICAL9.8An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipul...
CVE-2020-11722CRITICAL9.8Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytec...
CVE-2020-11710CRITICAL9.8An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces othe...
CVE-2020-11708CRITICAL9.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetU...
CVE-2020-11705CRITICAL9.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to loa...
CVE-2020-3952CRITICAL9.8Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi...
CVE-2020-8961CRITICAL9.8An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a w...
CVE-2020-10631CRITICAL9.8An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0...
CVE-2020-10625CRITICAL9.8WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.
CVE-2020-10619CRITICAL9.1An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) cont...
CVE-2020-10621CRITICAL9.8Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).
CVE-2020-11656CRITICAL9.8In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause tha...
CVE-2020-1615CRITICAL9.8The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without ...
CVE-2020-1614CRITICAL10A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) in...
CVE-2020-1992CRITICAL9.8A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC)...
CVE-2020-10980CRITICAL9.8GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now