2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-19364HIGH8.8OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
CVE-2020-19363MEDIUM6.5Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directori...
CVE-2020-19362MEDIUM6.1Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performi...
CVE-2020-19361MEDIUM6.1Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing mal...
CVE-2020-19360HIGH7.5Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a fil...
CVE-2020-29598Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its request...
CVE-2020-28707MEDIUM6.1The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_c...
CVE-2020-27269MEDIUM5.7In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and...
CVE-2020-27268MEDIUM6.5In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin...
CVE-2020-27266MEDIUM6.5In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin...
CVE-2020-11997MEDIUM4.3Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. I...
CVE-2020-27264HIGH8.8In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and...
CVE-2020-27258MEDIUM6.5In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the com...
CVE-2020-27256MEDIUM6.8In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu o...
CVE-2020-14410MEDIUM5.4SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in vi...
CVE-2020-14409HIGH7.8SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_...
CVE-2020-8581MEDIUM6.5Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authentica...
CVE-2020-35929CRITICAL9.8In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to...
CVE-2020-27276MEDIUM5.7SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyD...
CVE-2020-27272MEDIUM5.7SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i...
CVE-2020-27270MEDIUM5.7SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDa...
CVE-2020-4881HIGH7.5IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server h...
CVE-2020-4873MEDIUM5.3IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS poli...
CVE-2020-4871MEDIUM5.5IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-...
CVE-2020-27733HIGH8.8Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmvi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now