2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28329CRITICAL9.8Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the...
CVE-2020-25654HIGH7.2An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group c...
CVE-2020-25159CRITICAL9.8499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker...
CVE-2020-28334CRITICAL9.8Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2....
CVE-2020-28333CRITICAL9.8Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1...
CVE-2020-28332CRITICAL9.8Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5...
CVE-2020-28330MEDIUM6.5Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker ...
CVE-2020-25640MEDIUM5.3A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning lev...
CVE-2020-28994CRITICAL9.8A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and belo...
CVE-2020-28928MEDIUM5.5In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source characte...
CVE-2020-28331HIGH7.5Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-...
CVE-2020-13942CRITICAL9.8It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed...
CVE-2020-13620HIGH8.8Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading ...
CVE-2020-7378CRITICAL9.1CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attac...
CVE-2020-29040HIGH8.8An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corrup...
CVE-2020-28726MEDIUM6.1Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.
CVE-2020-24815MEDIUM6.5A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 ...
CVE-2020-10763MEDIUM5.5An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an...
CVE-2020-10762MEDIUM5.5An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block C...
CVE-2020-4003MEDIUM6.5VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulne...
CVE-2020-4002HIGH7.2The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameter...
CVE-2020-4001CRITICAL9.8The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orches...
CVE-2020-4000HIGH8.8The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing fil...
CVE-2020-3985HIGH8.8The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization...
CVE-2020-3984MEDIUM6.5The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now