2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7569 | HIGH | 8.8 | 2.3% | Nov 19, 2020 | A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebRepo... |
| CVE-2020-7566 | HIGH | 7.3 | 0.3% | Nov 19, 2020 | A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could a... |
| CVE-2020-7565 | HIGH | 7.3 | 0.3% | Nov 19, 2020 | A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could... |
| CVE-2020-7559 | HIGH | 7.5 | 1.9% | Nov 19, 2020 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator ... |
| CVE-2020-7558 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re... |
| CVE-2020-7557 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Rem... |
| CVE-2020-7556 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re... |
| CVE-2020-7555 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re... |
| CVE-2020-7554 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio... |
| CVE-2020-7553 | HIGH | 7.8 | 2.3% | Nov 19, 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re... |
| CVE-2020-7552 | HIGH | 7.8 | 1.6% | Nov 19, 2020 | A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause ... |
| CVE-2020-7551 | HIGH | 7.8 | 1.6% | Nov 19, 2020 | A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause ... |
| CVE-2020-7550 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio... |
| CVE-2020-7544 | HIGH | 7.8 | 0.3% | Nov 19, 2020 | A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD)... |
| CVE-2020-7538 | HIGH | 7.5 | 1.3% | Nov 19, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Co... |
| CVE-2020-28213 | HIGH | 8.8 | 1.1% | Nov 19, 2020 | A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert... |
| CVE-2020-28211 | HIGH | 7.8 | 0.3% | Nov 19, 2020 | A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) ... |
| CVE-2020-28209 | HIGH | 7 | 0.3% | Nov 19, 2020 | A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installe... |
| CVE-2020-25989 | HIGH | 7.8 | 0.7% | Nov 19, 2020 | Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exp... |
| CVE-2020-28924 | HIGH | 7.5 | 1.3% | Nov 19, 2020 | An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generato... |
| CVE-2020-28949 | HIGH | 7.8 | 84.6% | Nov 19, 2020 | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper... |
| CVE-2020-28948 | HIGH | 7.8 | 47.5% | Nov 19, 2020 | Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. |
| CVE-2020-12510 | HIGH | 7.3 | 0.8% | Nov 19, 2020 | The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory... |
| CVE-2020-12495 | HIGH | 8.8 | 0.9% | Nov 19, 2020 | Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to impr... |
| CVE-2020-25699 | HIGH | 7.5 | 1.6% | Nov 19, 2020 | In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capab... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now