2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-4128MEDIUM5.3HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker ...
CVE-2020-15257MEDIUM5.2containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd b...
CVE-2020-4129MEDIUM5.3HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker coul...
CVE-2020-4126MEDIUM5.9HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacke...
CVE-2020-14193MEDIUM5.4Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache template...
CVE-2020-4127MEDIUM6.5HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into ac...
CVE-2020-29441MEDIUM6.5An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker c...
CVE-2020-29440MEDIUM4.6Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob w...
CVE-2020-29439MEDIUM4.6Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a ...
CVE-2020-29438MEDIUM6.5Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This...
CVE-2020-29395MEDIUM6.1The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
CVE-2020-27587MEDIUM6.7Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vau...
CVE-2020-27586MEDIUM5.9Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
CVE-2020-27585MEDIUM4.4Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings v...
CVE-2020-17901MEDIUM6.5Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
CVE-2020-29392MEDIUM4.6The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical acce...
CVE-2020-29364MEDIUM4.8In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news tit...
CVE-2020-4900MEDIUM5.5IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a ...
CVE-2020-4696MEDIUM4.3IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated use...
CVE-2020-4626MEDIUM4.3IBM Cloud Pak for Security 1.3.0.1 (CP4S) could reveal sensitive information about the internal network to an authentica...
CVE-2020-4625MEDIUM5.3IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the fa...
CVE-2020-4624MEDIUM5.3IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could al...
CVE-2020-29384MEDIUM5.5An issue was discovered in PNGOUT 2020-01-15. When compressing a crafted PNG file, it encounters an integer overflow.
CVE-2020-28978MEDIUM5.3The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a...
CVE-2020-28977MEDIUM5.3The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now