2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11050 | HIGH | 8.1 | 0.8% | May 7, 2020 | In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where W... |
| CVE-2020-10795 | HIGH | 7.2 | 3.8% | May 7, 2020 | Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web... |
| CVE-2020-12116 | HIGH | 7.5 | 97.4% | May 7, 2020 | Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attack... |
| CVE-2020-7803 | HIGH | 8.8 | 1.2% | May 7, 2020 | IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donw... |
| CVE-2020-10974 | HIGH | 7.5 | 1.7% | May 7, 2020 | An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the... |
| CVE-2020-10973 | HIGH | 7.5 | 7.8% | May 7, 2020 | An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/Ex... |
| CVE-2020-10972 | HIGH | 7.5 | 1.7% | May 7, 2020 | An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source c... |
| CVE-2020-10971 | HIGH | 8.8 | 2.7% | May 7, 2020 | An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will resul... |
| CVE-2020-5745 | HIGH | 7.4 | 0.8% | May 7, 2020 | Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by trickin... |
| CVE-2020-12608 | HIGH | 7.8 | 22.4% | May 7, 2020 | An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni... |
| CVE-2020-6652 | HIGH | 7.8 | 0.4% | May 7, 2020 | Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin us... |
| CVE-2020-6651 | HIGH | 7.3 | 2.1% | May 7, 2020 | Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration fi... |
| CVE-2020-8983 | HIGH | 7.5 | 4.5% | May 7, 2020 | An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, in... |
| CVE-2020-8982 | HIGH | 7.5 | 27.1% | May 7, 2020 | An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones)... |
| CVE-2020-7473 | HIGH | 7.5 | 14.3% | May 7, 2020 | In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most ... |
| CVE-2020-6081 | HIGH | 8.8 | 1.8% | May 7, 2020 | An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH COD... |
| CVE-2020-5895 | HIGH | 7.8 | 0.3% | May 7, 2020 | On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which a... |
| CVE-2020-5894 | HIGH | 8.1 | 1.0% | May 7, 2020 | On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users lo... |
| CVE-2020-12691 | HIGH | 8.8 | 4.9% | May 7, 2020 | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 creden... |
| CVE-2020-12690 | HIGH | 8.8 | 1.9% | May 7, 2020 | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access... |
| CVE-2020-12689 | HIGH | 8.8 | 1.6% | May 7, 2020 | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (... |
| CVE-2020-12669 | HIGH | 8.8 | 2.0% | May 6, 2020 | core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restricti... |
| CVE-2020-3334 | HIGH | 7.4 | 0.4% | May 6, 2020 | A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thr... |
| CVE-2020-3312 | HIGH | 7.5 | 1.1% | May 6, 2020 | A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an ... |
| CVE-2020-3309 | HIGH | 7.2 | 1.8% | May 6, 2020 | A vulnerability in Cisco Firepower Device Manager (FDM) On-Box software could allow an authenticated, remote attacker to... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now