2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25162 | HIGH | 7.5 | 1.8% | Apr 14, 2022 | A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module c... |
| CVE-2020-25156 | HIGH | 7.2 | 1.1% | Apr 14, 2022 | Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and... |
| CVE-2020-25152 | HIGH | 8.1 | 1.2% | Apr 14, 2022 | A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earl... |
| CVE-2020-25150 | HIGH | 8.8 | 1.4% | Apr 14, 2022 | A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module ... |
| CVE-2020-4668 | HIGH | 8.8 | 0.4% | Apr 8, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable... |
| CVE-2020-27376 | HIGH | 8.8 | 1.0% | Apr 7, 2022 | Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication. |
| CVE-2020-27374 | HIGH | 7.5 | 0.9% | Apr 7, 2022 | Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring. |
| CVE-2020-27373 | HIGH | 8.8 | 1.1% | Apr 7, 2022 | Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE. |
| CVE-2020-23349 | HIGH | 7.5 | 0.8% | Apr 5, 2022 | An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivit... |
| CVE-2020-28062 | HIGH | 7.2 | 2.4% | Apr 4, 2022 | An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getLi... |
| CVE-2020-25691 | HIGH | 7.5 | 1.3% | Apr 1, 2022 | A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a ... |
| CVE-2020-24771 | HIGH | 7.5 | 2.0% | Mar 30, 2022 | Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content. |
| CVE-2020-21554 | HIGH | 8.1 | 1.5% | Mar 25, 2022 | A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could ... |
| CVE-2020-24772 | HIGH | 8.8 | 0.6% | Mar 21, 2022 | In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that ... |
| CVE-2020-26008 | HIGH | 7.8 | 0.9% | Mar 20, 2022 | The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file up... |
| CVE-2020-26007 | HIGH | 7.8 | 0.9% | Mar 20, 2022 | An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitra... |
| CVE-2020-25197 | HIGH | 8.8 | 3.0% | Mar 18, 2022 | A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware v... |
| CVE-2020-25178 | HIGH | 8.8 | 1.6% | Mar 18, 2022 | ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communic... |
| CVE-2020-25721 | HIGH | 8.8 | 2.0% | Mar 16, 2022 | Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Li... |
| CVE-2020-36518 | HIGH | 7.5 | 4.9% | Mar 11, 2022 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested o... |
| CVE-2020-36517 | HIGH | 7.5 | 2.9% | Mar 10, 2022 | An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS oper... |
| CVE-2020-14111 | HIGH | 7.8 | 0.3% | Mar 10, 2022 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio... |
| CVE-2020-18326 | HIGH | 8.8 | 2.2% | Mar 4, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator f... |
| CVE-2020-22845 | HIGH | 7.5 | 1.2% | Feb 28, 2022 | A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via craf... |
| CVE-2020-22844 | HIGH | 7.5 | 1.2% | Feb 28, 2022 | A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via craf... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now