2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4850 | HIGH | 7.5 | 1.0% | May 20, 2021 | IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive i... |
| CVE-2020-21053 | MEDIUM | 6.1 | 0.7% | May 20, 2021 | Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary we... |
| CVE-2020-24396 | HIGH | 7.5 | 1.8% | May 20, 2021 | homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware ima... |
| CVE-2020-24395 | MEDIUM | 6.8 | 0.2% | May 20, 2021 | The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical acces... |
| CVE-2020-15522 | MEDIUM | 5.9 | 1.5% | May 20, 2021 | Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 ha... |
| CVE-2020-4765 | LOW | 3.3 | 0.2% | May 19, 2021 | IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another ... |
| CVE-2020-4646 | MEDIUM | 4.3 | 0.7% | May 19, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0... |
| CVE-2020-36365 | MEDIUM | 6.1 | 2.6% | May 19, 2021 | Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, ... |
| CVE-2020-36364 | CRITICAL | 9.1 | 1.8% | May 19, 2021 | An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs a... |
| CVE-2020-20266 | MEDIUM | 6.5 | 2.1% | May 19, 2021 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x proces... |
| CVE-2020-20264 | MEDIUM | 6.5 | 2.1% | May 19, 2021 | Mikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated ... |
| CVE-2020-20246 | MEDIUM | 6.5 | 2.7% | May 18, 2021 | Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated r... |
| CVE-2020-20245 | MEDIUM | 6.5 | 2.7% | May 18, 2021 | Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remo... |
| CVE-2020-20227 | MEDIUM | 6.5 | 3.1% | May 18, 2021 | Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenti... |
| CVE-2020-20220 | MEDIUM | 6.5 | 2.7% | May 18, 2021 | Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An a... |
| CVE-2020-19924 | MEDIUM | 5.4 | 0.5% | May 18, 2021 | In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks. |
| CVE-2020-20237 | MEDIUM | 6.5 | 2.8% | May 18, 2021 | Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. ... |
| CVE-2020-20236 | MEDIUM | 6.5 | 3.3% | May 18, 2021 | Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. ... |
| CVE-2020-20222 | MEDIUM | 6.5 | 3.2% | May 18, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer proces... |
| CVE-2020-20214 | MEDIUM | 6.5 | 3.1% | May 18, 2021 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authe... |
| CVE-2020-18178 | CRITICAL | 9.8 | 1.7% | May 18, 2021 | Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST re... |
| CVE-2020-24740 | MEDIUM | 4.3 | 0.4% | May 18, 2021 | An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=ed... |
| CVE-2020-23861 | MEDIUM | 5.5 | 0.6% | May 18, 2021 | A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.... |
| CVE-2020-20951 | CRITICAL | 9.8 | 4.0% | May 18, 2021 | In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files. |
| CVE-2020-24026 | MEDIUM | 6.1 | 0.9% | May 18, 2021 | TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. Ti... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now