2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-20139MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table ...
CVE-2020-20138MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
CVE-2020-12523CRITICAL9.1On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled ...
CVE-2020-12522CRITICAL9.8The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafte...
CVE-2020-12521MEDIUM6.5On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high...
CVE-2020-12519CRITICAL9.8On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to ope...
CVE-2020-12518MEDIUM5.5On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by readin...
CVE-2020-12517CRITICAL9On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed m...
CVE-2020-8466CRITICAL9.8A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved pas...
CVE-2020-8465CRITICAL9.8A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate sy...
CVE-2020-8464HIGH7.5A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests...
CVE-2020-8463HIGH7.5A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a glob...
CVE-2020-8462MEDIUM4.8A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow a...
CVE-2020-8461HIGH8.8A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an at...
CVE-2020-27010MEDIUM4.8A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow a...
CVE-2020-35545CRITICAL9.8Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
CVE-2020-26276CRITICAL9.8Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsi...
CVE-2020-4846LOW2.7IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a de...
CVE-2020-4845MEDIUM5.4IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2020-35491HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-35490HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-35489CRITICAL10The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote cod...
CVE-2020-15294HIGH7Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results ...
CVE-2020-15293MEDIUM5.5Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to ins...
CVE-2020-15292MEDIUM5.5Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, Int...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now