2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-9271MEDIUM6.5ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
CVE-2020-9267MEDIUM6.5SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
CVE-2020-9266MEDIUM6.5SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xaja...
CVE-2020-9264MEDIUM5.5ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a Z...
CVE-2020-6845MEDIUM6.1An issue was discovered in TopManage OLK 2020. As there is no ReadOnly on the Session cookie, the user and admin account...
CVE-2020-1842MEDIUM6.8Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X versio...
CVE-2020-1855MEDIUM6.1Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3...
CVE-2020-1843MEDIUM6.8Huawei HEGE-560 version 1.0.1.20(SP2), OSCA-550 version 1.0.0.71(SP1), OSCA-550A version 1.0.0.71(SP1), OSCA-550AX versi...
CVE-2020-1789MEDIUM6.8Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentic...
CVE-2020-1872MEDIUM4.6Huawei smart phones P10 Plus with versions earlier than 9.1.0.201(C01E75R1P12T8), earlier than 9.1.0.252(C185E2R1P9T8), ...
CVE-2020-1814MEDIUM5.3Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001...
CVE-2020-1882MEDIUM4.6Huawei mobile phones Ever-L29B versions earlier than 10.0.0.180(C185E6R3P3), earlier than 10.0.0.180(C432E6R1P7), earlie...
CVE-2020-1830MEDIUM5.3Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001...
CVE-2020-7959MEDIUM5.3LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application e...
CVE-2020-1853MEDIUM6.5GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an aut...
CVE-2020-1857MEDIUM5.5Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 version...
CVE-2020-9038MEDIUM5.4Joplin through 1.0.184 allows Arbitrary File Read via XSS.
CVE-2020-6850MEDIUM6.1Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML ...
CVE-2020-1692MEDIUM6.5Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same cours...
CVE-2020-7252MEDIUM5.5Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows lo...
CVE-2020-9033MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9032MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9031MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9030MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9029MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now