2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-7569HIGH8.8A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebRepo...
CVE-2020-7566HIGH7.3A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could a...
CVE-2020-7565HIGH7.3A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could...
CVE-2020-7559HIGH7.5A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator ...
CVE-2020-7558HIGH7.8A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re...
CVE-2020-7557HIGH7.8A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Rem...
CVE-2020-7556HIGH7.8A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re...
CVE-2020-7555HIGH7.8A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re...
CVE-2020-7554HIGH7.8A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio...
CVE-2020-7553HIGH7.8A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re...
CVE-2020-7552HIGH7.8A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause ...
CVE-2020-7551HIGH7.8A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause ...
CVE-2020-7550HIGH7.8A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio...
CVE-2020-7544HIGH7.8A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD)...
CVE-2020-7538HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Co...
CVE-2020-28213HIGH8.8A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert...
CVE-2020-28211HIGH7.8A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) ...
CVE-2020-28209HIGH7A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installe...
CVE-2020-25989HIGH7.8Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exp...
CVE-2020-28924HIGH7.5An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generato...
CVE-2020-28949HIGH7.8Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper...
CVE-2020-28948HIGH7.8Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CVE-2020-12510HIGH7.3The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory...
CVE-2020-12495HIGH8.8Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to impr...
CVE-2020-25699HIGH7.5In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capab...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now