2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10859MEDIUM6.5Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extracti...
CVE-2020-10630MEDIUM6.1SAE IT-systems FW-50 Remote Telemetry Unit (RTU). The software does not neutralize or incorrectly neutralizes user-contr...
CVE-2020-12144MEDIUM4.9The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it pos...
CVE-2020-12143MEDIUM4.9The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someo...
CVE-2020-12142MEDIUM4.91. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user ...
CVE-2020-8033MEDIUM6.1Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.
CVE-2020-5517MEDIUM6.5CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analys...
CVE-2020-8799MEDIUM4.8A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordP...
CVE-2020-11737MEDIUM6.1A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-M...
CVE-2020-12659MEDIUM6.7An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write ...
CVE-2020-12656MEDIUM5.5gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through...
CVE-2020-12655MEDIUM5.5An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may...
CVE-2020-12652MEDIUM4.1The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to h...
CVE-2020-10717MEDIUM6.5A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version...
CVE-2020-10700MEDIUM5.3A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with th...
CVE-2020-10686MEDIUM4.7A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user re...
CVE-2020-8896MEDIUM5.9A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 all...
CVE-2020-5337MEDIUM6.1RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attack...
CVE-2020-5336MEDIUM6.1RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could...
CVE-2020-5334MEDIUM6.1RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulner...
CVE-2020-5333MEDIUM4.3RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote ...
CVE-2020-5331MEDIUM5.5RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session informatio...
CVE-2020-10618MEDIUM5.5LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unau...
CVE-2020-1732MEDIUM4.2A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identi...
CVE-2020-10933MEDIUM5.3An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now