2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28213HIGH8.8A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert...
CVE-2020-28212CRITICAL9.8A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxur...
CVE-2020-28211HIGH7.8A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) ...
CVE-2020-28209HIGH7A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installe...
CVE-2020-28350MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in OPAC in Sokrates SOWA SowaSQL through 5.6.1 via the sowacgi.php typ...
CVE-2020-28210MEDIUM6.1A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoS...
CVE-2020-25989HIGH7.8Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exp...
CVE-2020-28924HIGH7.5An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generato...
CVE-2020-28951CRITICAL9.8libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package nam...
CVE-2020-28949HIGH7.8Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper...
CVE-2020-28948HIGH7.8Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CVE-2020-28941MEDIUM5.5An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers ...
CVE-2020-28947MEDIUM6.1In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
CVE-2020-22394MEDIUM6.1In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.
CVE-2020-12510HIGH7.3The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory...
CVE-2020-12496MEDIUM6.5Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45...
CVE-2020-12495HIGH8.8Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to impr...
CVE-2020-6879LOW3.5Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the we...
CVE-2020-28942MEDIUM4.3An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protoc...
CVE-2020-25703MEDIUM5.3The participants table download in Moodle always included user emails, but should have only done so when users' emails a...
CVE-2020-25702MEDIUM6.1In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. Thi...
CVE-2020-25701MEDIUM5.3If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabl...
CVE-2020-25700MEDIUM6.5In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versi...
CVE-2020-25699HIGH7.5In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capab...
CVE-2020-25698HIGH7.5Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing cou...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now