2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24633CRITICAL9.8There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending e...
CVE-2020-17530CRITICAL9.8Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected ...
CVE-2020-7560HIGH8.6A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (...
CVE-2020-7549MEDIUM5.3A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, ...
CVE-2020-7543HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega...
CVE-2020-7542HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega...
CVE-2020-7541MEDIUM5.3A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modi...
CVE-2020-7540CRITICAL9.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy O...
CVE-2020-7539HIGH7.5A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, L...
CVE-2020-7537HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Lega...
CVE-2020-7536HIGH7.5A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versio...
CVE-2020-7535HIGH7.5A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerabilit...
CVE-2020-28220MEDIUM6.8A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 ...
CVE-2020-28219HIGH7.8A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original rele...
CVE-2020-28218MEDIUM6.5A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and ...
CVE-2020-28217HIGH7.5A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that woul...
CVE-2020-28216HIGH7.5A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that woul...
CVE-2020-28215CRITICAL9.8A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide ...
CVE-2020-28214MEDIUM5.5A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versi...
CVE-2020-8908LOW3.3A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine...
CVE-2020-4829HIGH7.8IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the ksu user command to gain root ...
CVE-2020-35110Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-35090Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-35076Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-29311CRITICAL9.8Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now