2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28329 | CRITICAL | 9.8 | 1.5% | Nov 24, 2020 | Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the... |
| CVE-2020-25654 | HIGH | 7.2 | 2.0% | Nov 24, 2020 | An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group c... |
| CVE-2020-25159 | CRITICAL | 9.8 | 2.9% | Nov 24, 2020 | 499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker... |
| CVE-2020-28334 | CRITICAL | 9.8 | 4.7% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.... |
| CVE-2020-28333 | CRITICAL | 9.8 | 3.2% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1... |
| CVE-2020-28332 | CRITICAL | 9.8 | 1.1% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5... |
| CVE-2020-28330 | MEDIUM | 6.5 | 1.1% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker ... |
| CVE-2020-25640 | MEDIUM | 5.3 | 1.3% | Nov 24, 2020 | A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning lev... |
| CVE-2020-28994 | CRITICAL | 9.8 | 1.3% | Nov 24, 2020 | A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and belo... |
| CVE-2020-28928 | MEDIUM | 5.5 | 0.6% | Nov 24, 2020 | In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source characte... |
| CVE-2020-28331 | HIGH | 7.5 | 1.7% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-... |
| CVE-2020-13942 | CRITICAL | 9.8 | 68.4% | Nov 24, 2020 | It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed... |
| CVE-2020-13620 | HIGH | 8.8 | 0.5% | Nov 24, 2020 | Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading ... |
| CVE-2020-7378 | CRITICAL | 9.1 | 2.6% | Nov 24, 2020 | CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attac... |
| CVE-2020-29040 | HIGH | 8.8 | 0.4% | Nov 24, 2020 | An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corrup... |
| CVE-2020-28726 | MEDIUM | 6.1 | 0.6% | Nov 24, 2020 | Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php. |
| CVE-2020-24815 | MEDIUM | 6.5 | 2.1% | Nov 24, 2020 | A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 ... |
| CVE-2020-10763 | MEDIUM | 5.5 | 0.4% | Nov 24, 2020 | An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an... |
| CVE-2020-10762 | MEDIUM | 5.5 | 0.3% | Nov 24, 2020 | An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block C... |
| CVE-2020-4003 | MEDIUM | 6.5 | 1.1% | Nov 24, 2020 | VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulne... |
| CVE-2020-4002 | HIGH | 7.2 | 1.6% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameter... |
| CVE-2020-4001 | CRITICAL | 9.8 | 2.9% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orches... |
| CVE-2020-4000 | HIGH | 8.8 | 43.0% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing fil... |
| CVE-2020-3985 | HIGH | 8.8 | 1.4% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization... |
| CVE-2020-3984 | MEDIUM | 6.5 | 22.4% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now