2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-27185HIGH7.5Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully ex...
CVE-2020-27184MEDIUM5.9The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support th...
CVE-2020-27150HIGH7.5In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of...
CVE-2020-27149MEDIUM6.5By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege leve...
CVE-2020-27020HIGH7.5Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially all...
CVE-2020-23996HIGH8.8A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to exe...
CVE-2020-23995MEDIUM6.5An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to ...
CVE-2020-28063CRITICAL9.8A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
CVE-2020-27830MEDIUM5.5A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio...
CVE-2020-27823HIGH7.8A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJ...
CVE-2020-25713MEDIUM6.5A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_co...
CVE-2020-21342HIGH7.5Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
CVE-2020-20092CRITICAL9.8File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type t...
CVE-2020-27824MEDIUM5.5A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker w...
CVE-2020-14354LOW3.3A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddr...
CVE-2020-12526MEDIUM5.3TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff A...
CVE-2020-12967HIGH7.2The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code executio...
CVE-2020-36198MEDIUM6.7A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vu...
CVE-2020-36197HIGH8.8An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, th...
CVE-2020-28722MEDIUM5.4Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability...
CVE-2020-19275MEDIUM5.3An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal int...
CVE-2020-18165MEDIUM4.8Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands int...
CVE-2020-19274MEDIUM6.1A Cross SIte Scripting (XSS) vulnerability exists in Dhcms 2017-09-18 in guestbook via the message board, which could le...
CVE-2020-23790CRITICAL9.8An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.
CVE-2020-27840HIGH7.5A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause in...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now