2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29550 | HIGH | 7.5 | 1.4% | Dec 23, 2020 | An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection o... |
| CVE-2020-11720 | CRITICAL | 9.8 | 1.8% | Dec 23, 2020 | An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation,... |
| CVE-2020-11718 | HIGH | 7.4 | 0.8% | Dec 23, 2020 | An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are ... |
| CVE-2020-35586 | HIGH | 7.5 | 1.4% | Dec 23, 2020 | In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via th... |
| CVE-2020-35585 | HIGH | 7.5 | 1.4% | Dec 23, 2020 | In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/in... |
| CVE-2020-35584 | MEDIUM | 5.9 | 0.8% | Dec 23, 2020 | In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser ... |
| CVE-2020-35136 | HIGH | 7.2 | 6.4% | Dec 23, 2020 | Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard... |
| CVE-2020-25198 | HIGH | 8.8 | 1.1% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protection... |
| CVE-2020-25196 | CRITICAL | 9.8 | 1.4% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may ... |
| CVE-2020-25194 | HIGH | 8.8 | 1.0% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, whi... |
| CVE-2020-25192 | MEDIUM | 5.3 | 0.9% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be dis... |
| CVE-2020-25190 | CRITICAL | 9.8 | 0.7% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials o... |
| CVE-2020-25153 | HIGH | 7.5 | 1.2% | Dec 23, 2020 | The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong... |
| CVE-2020-35658 | MEDIUM | 5.3 | 0.5% | Dec 23, 2020 | SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted. |
| CVE-2020-35657 | HIGH | 7.2 | 2.4% | Dec 23, 2020 | Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme t... |
| CVE-2020-35656 | HIGH | 7.2 | 2.4% | Dec 23, 2020 | Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?req... |
| CVE-2020-28641 | HIGH | 7.1 | 0.8% | Dec 22, 2020 | In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the loca... |
| CVE-2020-29583 | CRITICAL | 9.8 | 90.0% | Dec 22, 2020 | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p... |
| CVE-2020-27338 | HIGH | 7.1 | 0.8% | Dec 22, 2020 | An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows a... |
| CVE-2020-27337 | HIGH | 7.3 | 1.5% | Dec 22, 2020 | An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthe... |
| CVE-2020-27336 | MEDIUM | 5.3 | 1.7% | Dec 22, 2020 | An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a p... |
| CVE-2020-25066 | CRITICAL | 9.8 | 3.3% | Dec 22, 2020 | A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denia... |
| CVE-2020-24683 | CRITICAL | 9.8 | 1.4% | Dec 22, 2020 | The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which reli... |
| CVE-2020-24680 | HIGH | 7 | 0.3% | Dec 22, 2020 | In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stor... |
| CVE-2020-24679 | CRITICAL | 9.8 | 1.7% | Dec 22, 2020 | A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this fla... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now