2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4788MEDIUM4.7IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the dat...
CVE-2020-7573MEDIUM6.5A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that cou...
CVE-2020-7572HIGH8.8A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation W...
CVE-2020-7571MEDIUM5.4A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerabi...
CVE-2020-7570MEDIUM5.4A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists ...
CVE-2020-7569HIGH8.8A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebRepo...
CVE-2020-7568MEDIUM4.3A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all referenc...
CVE-2020-7567MEDIUM5.7A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that...
CVE-2020-7566HIGH7.3A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could a...
CVE-2020-7565HIGH7.3A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could...
CVE-2020-7561CRITICAL9.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and olde...
CVE-2020-7559HIGH7.5A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator ...
CVE-2020-7558HIGH7.8A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re...
CVE-2020-7557HIGH7.8A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Rem...
CVE-2020-7556HIGH7.8A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re...
CVE-2020-7555HIGH7.8A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re...
CVE-2020-7554HIGH7.8A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio...
CVE-2020-7553HIGH7.8A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re...
CVE-2020-7552HIGH7.8A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause ...
CVE-2020-7551HIGH7.8A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause ...
CVE-2020-7550HIGH7.8A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio...
CVE-2020-7544HIGH7.8A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD)...
CVE-2020-7538HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Co...
CVE-2020-28954MEDIUM5.3web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrate...
CVE-2020-28953MEDIUM4.3In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now