2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9117HIGH7.8HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5)...
CVE-2020-9114HIGH7.8FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper p...
CVE-2020-9116HIGH7.2Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker ...
CVE-2020-9115HIGH7.2ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command...
CVE-2020-4129MEDIUM5.3HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker coul...
CVE-2020-4126MEDIUM5.9HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacke...
CVE-2020-14193MEDIUM5.4Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache template...
CVE-2020-4127MEDIUM6.5HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into ac...
CVE-2020-29441MEDIUM6.5An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker c...
CVE-2020-29440MEDIUM4.6Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob w...
CVE-2020-29439MEDIUM4.6Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a ...
CVE-2020-29438MEDIUM6.5Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This...
CVE-2020-16850HIGH7.5Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by ...
CVE-2020-16849HIGH7.5An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in...
CVE-2020-11867LOW3.3Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary...
CVE-2020-29395MEDIUM6.1The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
CVE-2020-27587MEDIUM6.7Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vau...
CVE-2020-27586MEDIUM5.9Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text.
CVE-2020-27585MEDIUM4.4Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings v...
CVE-2020-8351HIGH7.8A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an a...
CVE-2020-6317LOW3.5In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can acc...
CVE-2020-29394HIGH7.8A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log ...
CVE-2020-17901MEDIUM6.5Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
CVE-2020-29392MEDIUM4.6The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical acce...
CVE-2020-29390CRITICAL9.8Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that co...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now