2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-15924HIGH7.5There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is req...
CVE-2020-15923HIGH7.5Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
CVE-2020-7519HIGH7.5A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could al...
CVE-2020-7518HIGH7.5A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allo...
CVE-2020-7516HIGH7.8A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and pri...
CVE-2020-7515HIGH7.8A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and ...
CVE-2020-7514HIGH7.8A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and...
CVE-2020-7491HIGH7.5**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 t...
CVE-2020-15633HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86...
CVE-2020-15632HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-84...
CVE-2020-15631HIGH8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1...
CVE-2020-10922HIGH7.5This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE H...
CVE-2020-10918HIGH7.5This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware...
CVE-2020-15887HIGH8.8A SQL injection vulnerability in softwareupdate_controller.php in the Software Update module before 1.6 for MunkiReport ...
CVE-2020-15886HIGH8.8A SQL injection vulnerability in reportdata_controller.php in the reportdata module before 3.5 for MunkiReport allows at...
CVE-2020-15884HIGH8.8A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL co...
CVE-2020-15882HIGH8.1A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines fr...
CVE-2020-11440HIGH7.5httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.
CVE-2020-15688HIGH8.8The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks...
CVE-2020-15908HIGH7.5tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction fro...
CVE-2020-15904HIGH7.8A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond all...
CVE-2020-15901HIGH8.8In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsub...
CVE-2020-4400HIGH7.5IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker t...
CVE-2020-4372HIGH7.8IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local use...
CVE-2020-9687HIGH8.8Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exp...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now