2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5032MEDIUM4.3IBM QRadar SIEM 7.3 and 7.4 in some configurations may be vulnerable to a temporary denial of service attack when sent p...
CVE-2020-4828MEDIUM6.5IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, cause...
CVE-2020-4827MEDIUM4.3IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery...
CVE-2020-4826MEDIUM4.3IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery...
CVE-2020-4825MEDIUM5.4IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This...
CVE-2020-4640MEDIUM4.1Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensit...
CVE-2020-27873MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG...
CVE-2020-27872HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450...
CVE-2020-28450HIGH8.6This affects all versions of package decal. The vulnerability is in the extend function.
CVE-2020-28449HIGH8.6This affects all versions of package decal. The vulnerability is in the set function.
CVE-2020-16194MEDIUM5.3An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated at...
CVE-2020-6088HIGH7.5An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Br...
CVE-2020-27249HIGH7.8A specially crafted document can cause the document parser to copy data from a particular record type into a static-size...
CVE-2020-27248HIGH7.8A specially crafted document can cause the document parser to copy data from a particular record type into a static-size...
CVE-2020-27247HIGH7.8A specially crafted document can cause the document parser to copy data from a particular record type into a static-size...
CVE-2020-14247MEDIUM6.5HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to...
CVE-2020-14246HIGH7.5HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potenti...
CVE-2020-14245CRITICAL9.8HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable ...
CVE-2020-13586HIGH7.8A memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software Gmb...
CVE-2020-13580HIGH7.8An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMa...
CVE-2020-13579HIGH7.8An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office...
CVE-2020-9390MEDIUM5.4SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content...
CVE-2020-9389LOW3.7A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented i...
CVE-2020-9388MEDIUM6.5CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administ...
CVE-2020-8589LOW3.5Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthoriz...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now