2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2020-14481HIGH7.8The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticat...
CVE-2020-14478HIGH7.1A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to ...
CVE-2020-10636HIGH7.5Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obta...
CVE-2020-27467HIGH7.5A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.
CVE-2020-8242HIGH7.2Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user ne...
CVE-2020-25722HIGH8.8Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker...
CVE-2020-25719HIGH7.2A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authenticat...
CVE-2020-25718HIGH8.8A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domai...
CVE-2020-25717HIGH8.1A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cau...
CVE-2020-8107HIGH7.8A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper...
CVE-2020-6922HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6921HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6919HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6918HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6917HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-13677HIGH7.5Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which ma...
CVE-2020-13670HIGH7.5Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadat...
CVE-2020-7534HIGH8.8A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sen...
CVE-2020-12965HIGH7.5When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using onl...
CVE-2020-12891HIGH7.8AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop i...
CVE-2020-5953HIGH7.5A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI h...
CVE-2020-28885HIGH7.2Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje...
CVE-2020-28884HIGH7.2Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje...
CVE-2020-4876HIGH8.2IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2020-4875HIGH8.2IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when pro...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now