2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-17485CRITICAL9.8A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by ...
CVE-2020-17484MEDIUM6.1An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL wit...
CVE-2020-17483HIGH7.5An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information...
CVE-2020-10676HIGH8.8In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have ce...
CVE-2020-28369HIGH7.8In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be...
CVE-2020-12614HIGH7.8An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is select...
CVE-2020-12612HIGH7.8An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevat...
CVE-2020-12615HIGH7.8An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to ...
CVE-2020-12613HIGH8.8An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. An attacker can spawn a process wit...
CVE-2020-25835MEDIUM5.4A potential vulnerability has been identified in Micro Focus ArcSight Management Center. The vulnerability could be remo...
CVE-2020-36768CRITICAL9.8A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an u...
CVE-2020-11448MEDIUM6.1An issue was discovered on Bell HomeHub 3000 SG48222070 devices. There is XSS related to the email field and the login p...
CVE-2020-11447MEDIUM4.3An issue was discovered on Bell HomeHub 3000 SG48222070 devices. Remote authenticated users can retrieve the serial numb...
CVE-2020-28407HIGH7.1In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink at...
CVE-2020-36767HIGH7.5tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input da...
CVE-2020-25870Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-17477MEDIUM6.5Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and s...
CVE-2020-36759MEDIUM4.3The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin...
CVE-2020-36758MEDIUM4.3The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc...
CVE-2020-36755MEDIUM4.3The Customizr theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. T...
CVE-2020-36754MEDIUM4.3The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ...
CVE-2020-36753MEDIUM4.3The Hueman theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This...
CVE-2020-36751MEDIUM4.3The Coupon Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3....
CVE-2020-36714HIGH8.1The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_admin...
CVE-2020-36706CRITICAL9.8The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now