2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-21989HIGH8.8HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform...
CVE-2020-21987MEDIUM6.1HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed v...
CVE-2020-4981MEDIUM6IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input ...
CVE-2020-35542MEDIUM5.4Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be...
CVE-2020-17517HIGH7.5The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The curren...
CVE-2020-36325HIGH7.5An issue was discovered in Jansson through 2.13.1. Due to a parsing error in json_loads, there's an out-of-bounds read-a...
CVE-2020-4562MEDIUM5.3IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window commun...
CVE-2020-15078HIGH7.5OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on...
CVE-2020-7036MEDIUM6.5An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain rea...
CVE-2020-7035MEDIUM6.5An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could a...
CVE-2020-7034HIGH8.8A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote...
CVE-2020-17542MEDIUM5.4Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious p...
CVE-2020-7385HIGH8.8By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the sa...
CVE-2020-36321HIGH7.5Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0....
CVE-2020-36320HIGH7.5Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 ...
CVE-2020-36319MEDIUM6.5Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 thr...
CVE-2020-17564CRITICAL9.1Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to ...
CVE-2020-17563CRITICAL9.1Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to ...
CVE-2020-27738HIGH7.4A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether...
CVE-2020-27737MEDIUM6.5A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether...
CVE-2020-27736MEDIUM6.5A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether...
CVE-2020-27009HIGH8.1A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether...
CVE-2020-26997HIGH7.8A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < ...
CVE-2020-25244HIGH8.4A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries...
CVE-2020-25243MEDIUM5.1A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be trigg...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now