2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29550HIGH7.5An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection o...
CVE-2020-11720CRITICAL9.8An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation,...
CVE-2020-11718HIGH7.4An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are ...
CVE-2020-35586HIGH7.5In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via th...
CVE-2020-35585HIGH7.5In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/in...
CVE-2020-35584MEDIUM5.9In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser ...
CVE-2020-35136HIGH7.2Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard...
CVE-2020-25198HIGH8.8The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protection...
CVE-2020-25196CRITICAL9.8The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may ...
CVE-2020-25194HIGH8.8The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, whi...
CVE-2020-25192MEDIUM5.3The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be dis...
CVE-2020-25190CRITICAL9.8The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials o...
CVE-2020-25153HIGH7.5The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong...
CVE-2020-35658MEDIUM5.3SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
CVE-2020-35657HIGH7.2Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme t...
CVE-2020-35656HIGH7.2Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?req...
CVE-2020-28641HIGH7.1In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the loca...
CVE-2020-29583CRITICAL9.8Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p...
CVE-2020-27338HIGH7.1An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows a...
CVE-2020-27337HIGH7.3An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthe...
CVE-2020-27336MEDIUM5.3An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a p...
CVE-2020-25066CRITICAL9.8A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denia...
CVE-2020-24683CRITICAL9.8The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which reli...
CVE-2020-24680HIGH7In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stor...
CVE-2020-24679CRITICAL9.8A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this fla...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now