2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11908 | MEDIUM | 4.3 | 1.9% | Jun 17, 2020 | The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP. |
| CVE-2020-11907 | MEDIUM | 6.3 | 2.0% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP. |
| CVE-2020-11906 | MEDIUM | 6.3 | 2.0% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow. |
| CVE-2020-11905 | MEDIUM | 6.5 | 2.1% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read. |
| CVE-2020-11903 | MEDIUM | 6.5 | 2.1% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read. |
| CVE-2020-11899 | MEDIUM | 5.4 | 18.4% | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. |
| CVE-2020-14214 | MEDIUM | 6.5 | 0.7% | Jun 16, 2020 | Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decis... |
| CVE-2020-14213 | MEDIUM | 5.4 | 0.6% | Jun 16, 2020 | In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data... |
| CVE-2020-4053 | MEDIUM | 6.8 | 1.5% | Jun 16, 2020 | In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plu... |
| CVE-2020-4052 | MEDIUM | 6.1 | 0.8% | Jun 16, 2020 | In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists ... |
| CVE-2020-14210 | MEDIUM | 6.1 | 1.0% | Jun 16, 2020 | Reflected Cross-Site Scripting (XSS) vulnerability in MONITORAPP WAF in which script can be executed when responding to ... |
| CVE-2020-7504 | MEDIUM | 5.3 | 1.3% | Jun 16, 2020 | A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could ... |
| CVE-2020-7499 | MEDIUM | 6.5 | 0.8% | Jun 16, 2020 | A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed i... |
| CVE-2020-7495 | MEDIUM | 5.5 | 0.9% | Jun 16, 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file e... |
| CVE-2020-7492 | MEDIUM | 6.5 | 1.1% | Jun 16, 2020 | A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the dis... |
| CVE-2020-14199 | MEDIUM | 6.5 | 0.8% | Jun 16, 2020 | BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to ... |
| CVE-2020-10268 | MEDIUM | 6.1 | 0.3% | Jun 16, 2020 | Critical services for operation can be terminated from windows task manager, bringing the manipulator to a halt. After t... |
| CVE-2020-9522 | MEDIUM | 6.1 | 0.6% | Jun 16, 2020 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting ve... |
| CVE-2020-8544 | MEDIUM | 6.5 | 1.1% | Jun 16, 2020 | OX App Suite through 7.10.3 allows SSRF. |
| CVE-2020-8542 | MEDIUM | 5.4 | 1.2% | Jun 16, 2020 | OX App Suite through 7.10.3 allows XSS. |
| CVE-2020-8541 | MEDIUM | 6.5 | 1.0% | Jun 16, 2020 | OX App Suite through 7.10.3 allows XXE attacks. |
| CVE-2020-4320 | MEDIUM | 6.5 | 0.8% | Jun 16, 2020 | IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients base... |
| CVE-2020-12494 | MEDIUM | 5.3 | 1.0% | Jun 16, 2020 | Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implement... |
| CVE-2020-11841 | MEDIUM | 4.3 | 0.7% | Jun 16, 2020 | Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions ... |
| CVE-2020-11840 | MEDIUM | 4.3 | 0.7% | Jun 16, 2020 | Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now