2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25647HIGH7.6A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very li...
CVE-2020-25632HIGH8.2A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a...
CVE-2020-14372HIGH7.5A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Sec...
CVE-2020-13554HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCAD...
CVE-2020-35296HIGH7.5ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboar...
CVE-2020-15937MEDIUM6.1An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow...
CVE-2020-10519HIGH8.8A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a...
CVE-2020-12530MEDIUM6.1An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There ...
CVE-2020-12529MEDIUM5.3An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There i...
CVE-2020-12528HIGH7.7An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improp...
CVE-2020-12527MEDIUM6.5An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all ve...
CVE-2020-28657CRITICAL9.8In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL...
CVE-2020-4726LOW3.3The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be r...
CVE-2020-4725LOW3.5IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially cr...
CVE-2020-4719MEDIUM4.9The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management ...
CVE-2020-23518MEDIUM5.4Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to vers...
CVE-2020-25902MEDIUM6.1Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execu...
CVE-2020-1936MEDIUM6.1A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
CVE-2020-36240MEDIUM5.3The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthe...
CVE-2020-9479MEDIUM5.5When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory....
CVE-2020-7929MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a...
CVE-2020-35662HIGH7.4In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not alway...
CVE-2020-28972MEDIUM5.9In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) do...
CVE-2020-28243HIGH7.8An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection vi...
CVE-2020-36079HIGH7.2Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacke...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now