2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27185 | HIGH | 7.5 | 0.7% | May 14, 2021 | Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully ex... |
| CVE-2020-27184 | MEDIUM | 5.9 | 0.3% | May 14, 2021 | The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support th... |
| CVE-2020-27150 | HIGH | 7.5 | 1.1% | May 14, 2021 | In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of... |
| CVE-2020-27149 | MEDIUM | 6.5 | 0.7% | May 14, 2021 | By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege leve... |
| CVE-2020-27020 | HIGH | 7.5 | 0.7% | May 14, 2021 | Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially all... |
| CVE-2020-23996 | HIGH | 8.8 | 2.3% | May 13, 2021 | A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to exe... |
| CVE-2020-23995 | MEDIUM | 6.5 | 1.5% | May 13, 2021 | An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to ... |
| CVE-2020-28063 | CRITICAL | 9.8 | 1.3% | May 13, 2021 | A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. |
| CVE-2020-27830 | MEDIUM | 5.5 | 0.3% | May 13, 2021 | A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio... |
| CVE-2020-27823 | HIGH | 7.8 | 1.1% | May 13, 2021 | A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJ... |
| CVE-2020-25713 | MEDIUM | 6.5 | 2.1% | May 13, 2021 | A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_co... |
| CVE-2020-21342 | HIGH | 7.5 | 1.2% | May 13, 2021 | Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php. |
| CVE-2020-20092 | CRITICAL | 9.8 | 1.3% | May 13, 2021 | File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type t... |
| CVE-2020-27824 | MEDIUM | 5.5 | 1.6% | May 13, 2021 | A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker w... |
| CVE-2020-14354 | LOW | 3.3 | 0.5% | May 13, 2021 | A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddr... |
| CVE-2020-12526 | MEDIUM | 5.3 | 1.0% | May 13, 2021 | TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff A... |
| CVE-2020-12967 | HIGH | 7.2 | 1.7% | May 13, 2021 | The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code executio... |
| CVE-2020-36198 | MEDIUM | 6.7 | 1.1% | May 13, 2021 | A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vu... |
| CVE-2020-36197 | HIGH | 8.8 | 18.5% | May 13, 2021 | An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, th... |
| CVE-2020-28722 | MEDIUM | 5.4 | 0.6% | May 12, 2021 | Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability... |
| CVE-2020-19275 | MEDIUM | 5.3 | 1.2% | May 12, 2021 | An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal int... |
| CVE-2020-18165 | MEDIUM | 4.8 | 0.9% | May 12, 2021 | Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands int... |
| CVE-2020-19274 | MEDIUM | 6.1 | 0.9% | May 12, 2021 | A Cross SIte Scripting (XSS) vulnerability exists in Dhcms 2017-09-18 in guestbook via the message board, which could le... |
| CVE-2020-23790 | CRITICAL | 9.8 | 1.5% | May 12, 2021 | An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5. |
| CVE-2020-27840 | HIGH | 7.5 | 3.8% | May 12, 2021 | A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause in... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now