2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5032 | MEDIUM | 4.3 | 0.5% | Feb 4, 2021 | IBM QRadar SIEM 7.3 and 7.4 in some configurations may be vulnerable to a temporary denial of service attack when sent p... |
| CVE-2020-4828 | MEDIUM | 6.5 | 0.8% | Feb 4, 2021 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, cause... |
| CVE-2020-4827 | MEDIUM | 4.3 | 0.4% | Feb 4, 2021 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery... |
| CVE-2020-4826 | MEDIUM | 4.3 | 0.4% | Feb 4, 2021 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery... |
| CVE-2020-4825 | MEDIUM | 5.4 | 0.7% | Feb 4, 2021 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This... |
| CVE-2020-4640 | MEDIUM | 4.1 | 0.3% | Feb 4, 2021 | Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensit... |
| CVE-2020-27873 | MEDIUM | 6.5 | 0.6% | Feb 4, 2021 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG... |
| CVE-2020-27872 | HIGH | 8.8 | 0.9% | Feb 4, 2021 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450... |
| CVE-2020-28450 | HIGH | 8.6 | 1.8% | Feb 4, 2021 | This affects all versions of package decal. The vulnerability is in the extend function. |
| CVE-2020-28449 | HIGH | 8.6 | 1.8% | Feb 4, 2021 | This affects all versions of package decal. The vulnerability is in the set function. |
| CVE-2020-16194 | MEDIUM | 5.3 | 1.2% | Feb 4, 2021 | An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated at... |
| CVE-2020-6088 | HIGH | 7.5 | 3.5% | Feb 4, 2021 | An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Br... |
| CVE-2020-27249 | HIGH | 7.8 | 1.2% | Feb 4, 2021 | A specially crafted document can cause the document parser to copy data from a particular record type into a static-size... |
| CVE-2020-27248 | HIGH | 7.8 | 1.2% | Feb 4, 2021 | A specially crafted document can cause the document parser to copy data from a particular record type into a static-size... |
| CVE-2020-27247 | HIGH | 7.8 | 1.2% | Feb 4, 2021 | A specially crafted document can cause the document parser to copy data from a particular record type into a static-size... |
| CVE-2020-14247 | MEDIUM | 6.5 | 0.7% | Feb 4, 2021 | HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to... |
| CVE-2020-14246 | HIGH | 7.5 | 0.7% | Feb 4, 2021 | HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potenti... |
| CVE-2020-14245 | CRITICAL | 9.8 | 1.2% | Feb 4, 2021 | HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable ... |
| CVE-2020-13586 | HIGH | 7.8 | 1.5% | Feb 4, 2021 | A memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software Gmb... |
| CVE-2020-13580 | HIGH | 7.8 | 72.6% | Feb 4, 2021 | An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMa... |
| CVE-2020-13579 | HIGH | 7.8 | 72.6% | Feb 4, 2021 | An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office... |
| CVE-2020-9390 | MEDIUM | 5.4 | 0.9% | Feb 3, 2021 | SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content... |
| CVE-2020-9389 | LOW | 3.7 | 0.9% | Feb 3, 2021 | A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented i... |
| CVE-2020-9388 | MEDIUM | 6.5 | 0.8% | Feb 3, 2021 | CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administ... |
| CVE-2020-8589 | LOW | 3.5 | 0.5% | Feb 3, 2021 | Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthoriz... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now