2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29555HIGH8.1The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary file...
CVE-2020-28149CRITICAL9.6myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The compone...
CVE-2020-24985HIGH8.1An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuP...
CVE-2020-24982MEDIUM4.3An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick...
CVE-2020-28387MEDIUM5.5A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < ...
CVE-2020-28385HIGH7.8A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < ...
CVE-2020-25241HIGH7.5A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the aff...
CVE-2020-25240HIGH8.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can acces...
CVE-2020-25239HIGH8.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow una...
CVE-2020-25236MEDIUM5.5A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0...
CVE-2020-24877CRITICAL9.8A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access rest...
CVE-2020-4184HIGH7.3IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, wh...
CVE-2020-35358CRITICAL9.8DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, bot...
CVE-2020-35682HIGH8.8Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
CVE-2020-4831HIGH7.5IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an a...
CVE-2020-36282CRITICAL9.8JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result i...
CVE-2020-36281HIGH7.5Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
CVE-2020-36280HIGH7.5Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
CVE-2020-36279HIGH7.5Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptm...
CVE-2020-36278HIGH7.5Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
CVE-2020-24984HIGH8.8An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to tri...
CVE-2020-24983HIGH8.8An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTM...
CVE-2020-36277HIGH7.5Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in ...
CVE-2020-29045CRITICAL9.8The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of ...
CVE-2020-14989MEDIUM6.5An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker use...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now