2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29509MEDIUM5.6The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes ...
CVE-2020-29304MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and p...
CVE-2020-29303MEDIUM6.1A cross-site scripting (XSS) vulnerability in the SabaiApp Directories Pro plugin 1.3.45 for WordPress allows remote att...
CVE-2020-28861MEDIUM5.3OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV ...
CVE-2020-28860HIGH8.8OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating i...
CVE-2020-27252HIGH8.1Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update sys...
CVE-2020-25187CRITICAL9.8Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent...
CVE-2020-25183HIGH8.8Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authentica...
CVE-2020-20184CRITICAL9.8GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting...
CVE-2020-20183HIGH7.5Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier al...
CVE-2020-16104HIGH7.2SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit...
CVE-2020-16103HIGH8.8Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote ...
CVE-2020-16102HIGH8.2Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to cr...
CVE-2020-28859MEDIUM6.1OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple par...
CVE-2020-28858HIGH8.8OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the applica...
CVE-2020-28857MEDIUM6.1OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple pa...
CVE-2020-20136CRITICAL9.8QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to inse...
CVE-2020-35338CRITICAL9.8The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier...
CVE-2020-28856HIGH7.5OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP ...
CVE-2020-25179CRITICAL9.8GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net...
CVE-2020-25175CRITICAL9.8GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net...
CVE-2020-15733MEDIUM6.5An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to...
CVE-2020-35382HIGH7.2SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
CVE-2020-35378CRITICAL9.8SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands ...
CVE-2020-14268CRITICAL9.8A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now