2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-11908MEDIUM4.3The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.
CVE-2020-11907MEDIUM6.3The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.
CVE-2020-11906MEDIUM6.3The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.
CVE-2020-11905MEDIUM6.5The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.
CVE-2020-11903MEDIUM6.5The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.
CVE-2020-11899MEDIUM5.4The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
CVE-2020-14214MEDIUM6.5Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decis...
CVE-2020-14213MEDIUM5.4In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data...
CVE-2020-4053MEDIUM6.8In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plu...
CVE-2020-4052MEDIUM6.1In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists ...
CVE-2020-14210MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in MONITORAPP WAF in which script can be executed when responding to ...
CVE-2020-7504MEDIUM5.3A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could ...
CVE-2020-7499MEDIUM6.5A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed i...
CVE-2020-7495MEDIUM5.5A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file e...
CVE-2020-7492MEDIUM6.5A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the dis...
CVE-2020-14199MEDIUM6.5BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to ...
CVE-2020-10268MEDIUM6.1Critical services for operation can be terminated from windows task manager, bringing the manipulator to a halt. After t...
CVE-2020-9522MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting ve...
CVE-2020-8544MEDIUM6.5OX App Suite through 7.10.3 allows SSRF.
CVE-2020-8542MEDIUM5.4OX App Suite through 7.10.3 allows XSS.
CVE-2020-8541MEDIUM6.5OX App Suite through 7.10.3 allows XXE attacks.
CVE-2020-4320MEDIUM6.5IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients base...
CVE-2020-12494MEDIUM5.3Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implement...
CVE-2020-11841MEDIUM4.3Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions ...
CVE-2020-11840MEDIUM4.3Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now