2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15924 | HIGH | 7.5 | 1.9% | Jul 24, 2020 | There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is req... |
| CVE-2020-15923 | HIGH | 7.5 | 3.3% | Jul 24, 2020 | Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal. |
| CVE-2020-7519 | HIGH | 7.5 | 1.3% | Jul 23, 2020 | A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could al... |
| CVE-2020-7518 | HIGH | 7.5 | 1.1% | Jul 23, 2020 | A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allo... |
| CVE-2020-7516 | HIGH | 7.8 | 0.2% | Jul 23, 2020 | A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and pri... |
| CVE-2020-7515 | HIGH | 7.8 | 0.3% | Jul 23, 2020 | A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and ... |
| CVE-2020-7514 | HIGH | 7.8 | 0.2% | Jul 23, 2020 | A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and... |
| CVE-2020-7491 | HIGH | 7.5 | 1.3% | Jul 23, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 t... |
| CVE-2020-15633 | HIGH | 8.8 | 2.8% | Jul 23, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86... |
| CVE-2020-15632 | HIGH | 8.8 | 3.3% | Jul 23, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-84... |
| CVE-2020-15631 | HIGH | 8 | 2.9% | Jul 23, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1... |
| CVE-2020-10922 | HIGH | 7.5 | 3.7% | Jul 23, 2020 | This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE H... |
| CVE-2020-10918 | HIGH | 7.5 | 2.7% | Jul 23, 2020 | This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware... |
| CVE-2020-15887 | HIGH | 8.8 | 1.3% | Jul 23, 2020 | A SQL injection vulnerability in softwareupdate_controller.php in the Software Update module before 1.6 for MunkiReport ... |
| CVE-2020-15886 | HIGH | 8.8 | 1.3% | Jul 23, 2020 | A SQL injection vulnerability in reportdata_controller.php in the reportdata module before 3.5 for MunkiReport allows at... |
| CVE-2020-15884 | HIGH | 8.8 | 1.2% | Jul 23, 2020 | A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL co... |
| CVE-2020-15882 | HIGH | 8.1 | 0.6% | Jul 23, 2020 | A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines fr... |
| CVE-2020-11440 | HIGH | 7.5 | 1.1% | Jul 23, 2020 | httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root. |
| CVE-2020-15688 | HIGH | 8.8 | 4.0% | Jul 23, 2020 | The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks... |
| CVE-2020-15908 | HIGH | 7.5 | 1.7% | Jul 23, 2020 | tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction fro... |
| CVE-2020-15904 | HIGH | 7.8 | 1.1% | Jul 22, 2020 | A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond all... |
| CVE-2020-15901 | HIGH | 8.8 | 21.9% | Jul 22, 2020 | In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsub... |
| CVE-2020-4400 | HIGH | 7.5 | 1.6% | Jul 22, 2020 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker t... |
| CVE-2020-4372 | HIGH | 7.8 | 0.3% | Jul 22, 2020 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local use... |
| CVE-2020-9687 | HIGH | 8.8 | 3.5% | Jul 22, 2020 | Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exp... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now