2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-25162HIGH7.5A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module c...
CVE-2020-25156HIGH7.2Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and...
CVE-2020-25152HIGH8.1A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earl...
CVE-2020-25150HIGH8.8A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module ...
CVE-2020-4668HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable...
CVE-2020-27376HIGH8.8Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.
CVE-2020-27374HIGH7.5Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.
CVE-2020-27373HIGH8.8Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.
CVE-2020-23349HIGH7.5An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivit...
CVE-2020-28062HIGH7.2An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getLi...
CVE-2020-25691HIGH7.5A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a ...
CVE-2020-24771HIGH7.5Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
CVE-2020-21554HIGH8.1A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could ...
CVE-2020-24772HIGH8.8In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that ...
CVE-2020-26008HIGH7.8The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file up...
CVE-2020-26007HIGH7.8An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitra...
CVE-2020-25197HIGH8.8A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware v...
CVE-2020-25178HIGH8.8ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communic...
CVE-2020-25721HIGH8.8Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Li...
CVE-2020-36518HIGH7.5jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested o...
CVE-2020-36517HIGH7.5An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS oper...
CVE-2020-14111HIGH7.8A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio...
CVE-2020-18326HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator f...
CVE-2020-22845HIGH7.5A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via craf...
CVE-2020-22844HIGH7.5A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via craf...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now