2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-20093MEDIUM6.5The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly...
CVE-2020-25193MEDIUM5.3By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions...
CVE-2020-25184MEDIUM5.5Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same ...
CVE-2020-25182MEDIUM6.7Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled ...
CVE-2020-25180MEDIUM6.5Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is requir...
CVE-2020-15388MEDIUM6.5A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow ...
CVE-2020-36519MEDIUM4.9Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This o...
CVE-2020-4989MEDIUM4.3IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an...
CVE-2020-14112MEDIUM5.3Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing conf...
CVE-2020-18327MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter i...
CVE-2020-18325MEDIUM6.1Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
CVE-2020-18324MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
CVE-2020-15936MEDIUM4.5A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and b...
CVE-2020-4925MEDIUM5.5A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requ...
CVE-2020-36510MEDIUM6.1The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the r...
CVE-2020-27958MEDIUM4.3The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote auth...
CVE-2020-36516MEDIUM5.9An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID a...
CVE-2020-14504MEDIUM5.3The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, una...
CVE-2020-14502MEDIUM6.1The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker...
CVE-2020-14480MEDIUM5.5Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker coul...
CVE-2020-10635MEDIUM4.3Simulation models for KUKA.Sim Pro version 3.1 are hosted by a server maintained by KUKA. When these devices request a m...
CVE-2020-10632MEDIUM5.3Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of import...
CVE-2020-6920MEDIUM5.5Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-13676MEDIUM6.5The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclo...
CVE-2020-13674MEDIUM6.5The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under som...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now