2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19364 | HIGH | 8.8 | 70.6% | Jan 20, 2021 | OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php. |
| CVE-2020-19363 | MEDIUM | 6.5 | 3.6% | Jan 20, 2021 | Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directori... |
| CVE-2020-19362 | MEDIUM | 6.1 | 0.7% | Jan 20, 2021 | Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performi... |
| CVE-2020-19361 | MEDIUM | 6.1 | 1.0% | Jan 20, 2021 | Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing mal... |
| CVE-2020-19360 | HIGH | 7.5 | 20.2% | Jan 20, 2021 | Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a fil... |
| CVE-2020-29598 | — | — | — | Jan 19, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its request... |
| CVE-2020-28707 | MEDIUM | 6.1 | 1.4% | Jan 19, 2021 | The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_c... |
| CVE-2020-27269 | MEDIUM | 5.7 | 0.5% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and... |
| CVE-2020-27268 | MEDIUM | 6.5 | 0.5% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin... |
| CVE-2020-27266 | MEDIUM | 6.5 | 0.6% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin... |
| CVE-2020-11997 | MEDIUM | 4.3 | 1.2% | Jan 19, 2021 | Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. I... |
| CVE-2020-27264 | HIGH | 8.8 | 0.5% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and... |
| CVE-2020-27258 | MEDIUM | 6.5 | 0.6% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the com... |
| CVE-2020-27256 | MEDIUM | 6.8 | 0.3% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu o... |
| CVE-2020-14410 | MEDIUM | 5.4 | 1.7% | Jan 19, 2021 | SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in vi... |
| CVE-2020-14409 | HIGH | 7.8 | 1.3% | Jan 19, 2021 | SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_... |
| CVE-2020-8581 | MEDIUM | 6.5 | 0.9% | Jan 19, 2021 | Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authentica... |
| CVE-2020-35929 | CRITICAL | 9.8 | 1.0% | Jan 19, 2021 | In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to... |
| CVE-2020-27276 | MEDIUM | 5.7 | 0.5% | Jan 19, 2021 | SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyD... |
| CVE-2020-27272 | MEDIUM | 5.7 | 0.5% | Jan 19, 2021 | SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i... |
| CVE-2020-27270 | MEDIUM | 5.7 | 0.3% | Jan 19, 2021 | SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDa... |
| CVE-2020-4881 | HIGH | 7.5 | 0.9% | Jan 19, 2021 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server h... |
| CVE-2020-4873 | MEDIUM | 5.3 | 1.0% | Jan 19, 2021 | IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS poli... |
| CVE-2020-4871 | MEDIUM | 5.5 | 0.3% | Jan 19, 2021 | IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-... |
| CVE-2020-27733 | HIGH | 8.8 | 8.8% | Jan 19, 2021 | Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmvi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now