2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15125 | HIGH | 7.7 | 1.5% | Jul 29, 2020 | In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request obj... |
| CVE-2020-15099 | HIGH | 8.1 | 1.8% | Jul 29, 2020 | In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4... |
| CVE-2020-15098 | HIGH | 8.8 | 2.2% | Jul 29, 2020 | In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4... |
| CVE-2020-13699 | HIGH | 8.8 | 25.9% | Jul 29, 2020 | TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could ... |
| CVE-2020-4574 | HIGH | 7.5 | 1.9% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it eas... |
| CVE-2020-4463 | HIGH | 8.2 | 31.6% | Jul 29, 2020 | IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when proc... |
| CVE-2020-2077 | HIGH | 7.5 | 1.0% | Jul 29, 2020 | SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions ... |
| CVE-2020-14488 | HIGH | 8.8 | 1.7% | Jul 29, 2020 | OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to uplo... |
| CVE-2020-14486 | HIGH | 8.8 | 1.3% | Jul 29, 2020 | An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of... |
| CVE-2020-14493 | HIGH | 8.8 | 1.7% | Jul 29, 2020 | A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which... |
| CVE-2020-14490 | HIGH | 8.8 | 2.5% | Jul 29, 2020 | OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files... |
| CVE-2020-14489 | HIGH | 7.5 | 1.0% | Jul 29, 2020 | OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to ... |
| CVE-2020-6098 | HIGH | 7.5 | 1.8% | Jul 28, 2020 | An exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A special... |
| CVE-2020-13997 | HIGH | 7.5 | 1.5% | Jul 28, 2020 | In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and v... |
| CVE-2020-13970 | HIGH | 8.8 | 1.3% | Jul 28, 2020 | Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.... |
| CVE-2020-11476 | HIGH | 7.2 | 2.9% | Jul 28, 2020 | Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file. |
| CVE-2020-11474 | HIGH | 7.8 | 0.5% | Jul 28, 2020 | NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant. |
| CVE-2020-10984 | HIGH | 8.8 | 0.7% | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows admin/admin.php CSRF. |
| CVE-2020-16094 | HIGH | 7.5 | 1.8% | Jul 28, 2020 | In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because ... |
| CVE-2020-15899 | HIGH | 7.5 | 0.8% | Jul 28, 2020 | Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble. |
| CVE-2020-15419 | HIGH | 7.5 | 63.8% | Jul 28, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0... |
| CVE-2020-15418 | HIGH | 7.5 | 9.4% | Jul 28, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0... |
| CVE-2020-15416 | HIGH | 8.8 | 6.4% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700... |
| CVE-2020-10929 | HIGH | 8.8 | 1.9% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
| CVE-2020-10928 | HIGH | 8.4 | 0.6% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now