2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24633 | CRITICAL | 9.8 | 4.9% | Dec 11, 2020 | There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending e... |
| CVE-2020-17530 | CRITICAL | 9.8 | 95.9% | Dec 11, 2020 | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected ... |
| CVE-2020-7560 | HIGH | 8.6 | 1.4% | Dec 11, 2020 | A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (... |
| CVE-2020-7549 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, ... |
| CVE-2020-7543 | HIGH | 7.5 | 1.3% | Dec 11, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega... |
| CVE-2020-7542 | HIGH | 7.5 | 1.3% | Dec 11, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega... |
| CVE-2020-7541 | MEDIUM | 5.3 | 0.9% | Dec 11, 2020 | A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modi... |
| CVE-2020-7540 | CRITICAL | 9.8 | 2.1% | Dec 11, 2020 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy O... |
| CVE-2020-7539 | HIGH | 7.5 | 1.1% | Dec 11, 2020 | A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, L... |
| CVE-2020-7537 | HIGH | 7.5 | 1.4% | Dec 11, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega... |
| CVE-2020-7536 | HIGH | 7.5 | 1.1% | Dec 11, 2020 | A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versio... |
| CVE-2020-7535 | HIGH | 7.5 | 1.4% | Dec 11, 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerabilit... |
| CVE-2020-28220 | MEDIUM | 6.8 | 1.0% | Dec 11, 2020 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 ... |
| CVE-2020-28219 | HIGH | 7.8 | 0.3% | Dec 11, 2020 | A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original rele... |
| CVE-2020-28218 | MEDIUM | 6.5 | 1.1% | Dec 11, 2020 | A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and ... |
| CVE-2020-28217 | HIGH | 7.5 | 0.6% | Dec 11, 2020 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that woul... |
| CVE-2020-28216 | HIGH | 7.5 | 0.5% | Dec 11, 2020 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that woul... |
| CVE-2020-28215 | CRITICAL | 9.8 | 2.2% | Dec 11, 2020 | A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide ... |
| CVE-2020-28214 | MEDIUM | 5.5 | 0.7% | Dec 11, 2020 | A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versi... |
| CVE-2020-8908 | LOW | 3.3 | 1.0% | Dec 10, 2020 | A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine... |
| CVE-2020-4829 | HIGH | 7.8 | 0.3% | Dec 10, 2020 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root ... |
| CVE-2020-35110 | — | — | — | Dec 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-35090 | — | — | — | Dec 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-35076 | — | — | — | Dec 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-29311 | CRITICAL | 9.8 | 6.3% | Dec 10, 2020 | Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now