2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4788 | MEDIUM | 4.7 | 0.4% | Nov 20, 2020 | IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the dat... |
| CVE-2020-7573 | MEDIUM | 6.5 | 1.4% | Nov 19, 2020 | A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that cou... |
| CVE-2020-7572 | HIGH | 8.8 | 1.8% | Nov 19, 2020 | A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation W... |
| CVE-2020-7571 | MEDIUM | 5.4 | 0.8% | Nov 19, 2020 | A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerabi... |
| CVE-2020-7570 | MEDIUM | 5.4 | 0.8% | Nov 19, 2020 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists ... |
| CVE-2020-7569 | HIGH | 8.8 | 2.3% | Nov 19, 2020 | A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebRepo... |
| CVE-2020-7568 | MEDIUM | 4.3 | 0.5% | Nov 19, 2020 | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all referenc... |
| CVE-2020-7567 | MEDIUM | 5.7 | 0.2% | Nov 19, 2020 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that... |
| CVE-2020-7566 | HIGH | 7.3 | 0.3% | Nov 19, 2020 | A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could a... |
| CVE-2020-7565 | HIGH | 7.3 | 0.3% | Nov 19, 2020 | A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could... |
| CVE-2020-7561 | CRITICAL | 9.8 | 3.0% | Nov 19, 2020 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and olde... |
| CVE-2020-7559 | HIGH | 7.5 | 1.9% | Nov 19, 2020 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator ... |
| CVE-2020-7558 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re... |
| CVE-2020-7557 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Rem... |
| CVE-2020-7556 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re... |
| CVE-2020-7555 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re... |
| CVE-2020-7554 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio... |
| CVE-2020-7553 | HIGH | 7.8 | 2.3% | Nov 19, 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Re... |
| CVE-2020-7552 | HIGH | 7.8 | 1.6% | Nov 19, 2020 | A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause ... |
| CVE-2020-7551 | HIGH | 7.8 | 1.6% | Nov 19, 2020 | A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause ... |
| CVE-2020-7550 | HIGH | 7.8 | 2.4% | Nov 19, 2020 | A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definitio... |
| CVE-2020-7544 | HIGH | 7.8 | 0.3% | Nov 19, 2020 | A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD)... |
| CVE-2020-7538 | HIGH | 7.5 | 1.3% | Nov 19, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Co... |
| CVE-2020-28954 | MEDIUM | 5.3 | 1.2% | Nov 19, 2020 | web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrate... |
| CVE-2020-28953 | MEDIUM | 4.3 | 0.7% | Nov 19, 2020 | In BigBlueButton before 2.2.29, a user can vote more than once in a single poll. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now