2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24678 | HIGH | 8.8 | 1.5% | Dec 22, 2020 | An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations ... |
| CVE-2020-24677 | HIGH | 8.8 | 1.3% | Dec 22, 2020 | Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privile... |
| CVE-2020-24676 | HIGH | 7.8 | 0.4% | Dec 22, 2020 | In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks... |
| CVE-2020-24675 | CRITICAL | 9.8 | 1.2% | Dec 22, 2020 | In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations Histo... |
| CVE-2020-24674 | HIGH | 8.8 | 2.9% | Dec 22, 2020 | In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated bu... |
| CVE-2020-24673 | CRITICAL | 9.8 | 1.0% | Dec 22, 2020 | In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify ... |
| CVE-2020-14874 | MEDIUM | 4.7 | 0.8% | Dec 22, 2020 | Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily... |
| CVE-2020-14270 | MEDIUM | 5.3 | 0.9% | Dec 22, 2020 | HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handli... |
| CVE-2020-35609 | MEDIUM | 5.5 | 1.3% | Dec 22, 2020 | A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequ... |
| CVE-2020-35608 | HIGH | 7.8 | 4.0% | Dec 22, 2020 | A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Spher... |
| CVE-2020-14231 | HIGH | 8.8 | 1.0% | Dec 22, 2020 | A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an... |
| CVE-2020-24581 | HIGH | 8 | 12.6% | Dec 22, 2020 | An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_c... |
| CVE-2020-24580 | HIGH | 7.5 | 1.3% | Dec 22, 2020 | An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication f... |
| CVE-2020-24579 | HIGH | 8.8 | 10.0% | Dec 22, 2020 | An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attac... |
| CVE-2020-24578 | MEDIUM | 6.5 | 1.8% | Dec 22, 2020 | An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured F... |
| CVE-2020-13547 | HIGH | 8.8 | 2.8% | Dec 22, 2020 | A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.3752... |
| CVE-2020-25106 | HIGH | 7.8 | 1.5% | Dec 22, 2020 | Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename ... |
| CVE-2020-13570 | HIGH | 8.8 | 2.2% | Dec 22, 2020 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A s... |
| CVE-2020-13560 | HIGH | 8.8 | 2.9% | Dec 22, 2020 | A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.3752... |
| CVE-2020-13557 | HIGH | 8.8 | 70.9% | Dec 22, 2020 | A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.3752... |
| CVE-2020-29396 | HIGH | 8.8 | 3.2% | Dec 22, 2020 | A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3... |
| CVE-2020-28460 | HIGH | 8.1 | 1.5% | Dec 22, 2020 | This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the const... |
| CVE-2020-28448 | CRITICAL | 9.8 | 1.4% | Dec 22, 2020 | This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto... |
| CVE-2020-35626 | HIGH | 8.8 | 0.5% | Dec 21, 2020 | An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an... |
| CVE-2020-35625 | HIGH | 8.8 | 1.0% | Dec 21, 2020 | An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages w... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now