2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-15125HIGH7.7In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request obj...
CVE-2020-15099HIGH8.1In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4...
CVE-2020-15098HIGH8.8In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4...
CVE-2020-13699HIGH8.8TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could ...
CVE-2020-4574HIGH7.5IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it eas...
CVE-2020-4463HIGH8.2IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when proc...
CVE-2020-2077HIGH7.5SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions ...
CVE-2020-14488HIGH8.8OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to uplo...
CVE-2020-14486HIGH8.8An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of...
CVE-2020-14493HIGH8.8A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which...
CVE-2020-14490HIGH8.8OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files...
CVE-2020-14489HIGH7.5OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to ...
CVE-2020-6098HIGH7.5An exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A special...
CVE-2020-13997HIGH7.5In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and v...
CVE-2020-13970HIGH8.8Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature....
CVE-2020-11476HIGH7.2Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
CVE-2020-11474HIGH7.8NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.
CVE-2020-10984HIGH8.8Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.
CVE-2020-16094HIGH7.5In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because ...
CVE-2020-15899HIGH7.5Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
CVE-2020-15419HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0...
CVE-2020-15418HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0...
CVE-2020-15416HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700...
CVE-2020-10929HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...
CVE-2020-10928HIGH8.4This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now