2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15798CRITICAL9.8A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a)...
CVE-2020-10048MEDIUM5.5A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an ...
CVE-2020-4996MEDIUM5.5IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the...
CVE-2020-4995MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a use...
CVE-2020-4795HIGH8.2IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user usi...
CVE-2020-4791MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using ma...
CVE-2020-4790MEDIUM6.5IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperl...
CVE-2020-27261HIGH8.8The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to r...
CVE-2020-27259HIGH8.8The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which m...
CVE-2020-27257HIGH7.8This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplie...
CVE-2020-22841MEDIUM4.8Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution...
CVE-2020-22840MEDIUM6.1Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redi...
CVE-2020-16044HIGH8.8Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap co...
CVE-2020-13462MEDIUM5.7Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in...
CVE-2020-13461MEDIUM4.3Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided...
CVE-2020-13460HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions pri...
CVE-2020-13409MEDIUM5.9Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als...
CVE-2020-13408MEDIUM5.9Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als...
CVE-2020-13407MEDIUM5.9Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als...
CVE-2020-24685HIGH8.6An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vu...
CVE-2020-29021MEDIUM4.8A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause...
CVE-2020-14391MEDIUM5.5A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly us...
CVE-2020-8590LOW3.3Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacke...
CVE-2020-8587MEDIUM5.5OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that cou...
CVE-2020-8578LOW3.3Clustered Data ONTAP versions prior to 9.3P20 are susceptible to a vulnerability which could allow an attacker to discov...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now