2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-21989 | HIGH | 8.8 | 0.7% | Apr 27, 2021 | HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform... |
| CVE-2020-21987 | MEDIUM | 6.1 | 0.9% | Apr 27, 2021 | HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed v... |
| CVE-2020-4981 | MEDIUM | 6 | 0.2% | Apr 27, 2021 | IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input ... |
| CVE-2020-35542 | MEDIUM | 5.4 | 0.5% | Apr 27, 2021 | Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be... |
| CVE-2020-17517 | HIGH | 7.5 | 2.3% | Apr 27, 2021 | The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The curren... |
| CVE-2020-36325 | HIGH | 7.5 | 1.7% | Apr 26, 2021 | An issue was discovered in Jansson through 2.13.1. Due to a parsing error in json_loads, there's an out-of-bounds read-a... |
| CVE-2020-4562 | MEDIUM | 5.3 | 1.3% | Apr 26, 2021 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window commun... |
| CVE-2020-15078 | HIGH | 7.5 | 5.1% | Apr 26, 2021 | OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on... |
| CVE-2020-7036 | MEDIUM | 6.5 | 1.0% | Apr 23, 2021 | An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain rea... |
| CVE-2020-7035 | MEDIUM | 6.5 | 1.1% | Apr 23, 2021 | An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could a... |
| CVE-2020-7034 | HIGH | 8.8 | 2.4% | Apr 23, 2021 | A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote... |
| CVE-2020-17542 | MEDIUM | 5.4 | 0.8% | Apr 23, 2021 | Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious p... |
| CVE-2020-7385 | HIGH | 8.8 | 1.8% | Apr 23, 2021 | By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the sa... |
| CVE-2020-36321 | HIGH | 7.5 | 1.2% | Apr 23, 2021 | Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.... |
| CVE-2020-36320 | HIGH | 7.5 | 2.0% | Apr 23, 2021 | Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 ... |
| CVE-2020-36319 | MEDIUM | 6.5 | 1.0% | Apr 23, 2021 | Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 thr... |
| CVE-2020-17564 | CRITICAL | 9.1 | 2.6% | Apr 22, 2021 | Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to ... |
| CVE-2020-17563 | CRITICAL | 9.1 | 2.6% | Apr 22, 2021 | Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to ... |
| CVE-2020-27738 | HIGH | 7.4 | 3.7% | Apr 22, 2021 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether... |
| CVE-2020-27737 | MEDIUM | 6.5 | 3.6% | Apr 22, 2021 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether... |
| CVE-2020-27736 | MEDIUM | 6.5 | 3.6% | Apr 22, 2021 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether... |
| CVE-2020-27009 | HIGH | 8.1 | 7.2% | Apr 22, 2021 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether... |
| CVE-2020-26997 | HIGH | 7.8 | 1.0% | Apr 22, 2021 | A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < ... |
| CVE-2020-25244 | HIGH | 8.4 | 0.2% | Apr 22, 2021 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries... |
| CVE-2020-25243 | MEDIUM | 5.1 | 0.3% | Apr 22, 2021 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be trigg... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now