2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28213 | HIGH | 8.8 | 1.1% | Nov 19, 2020 | A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert... |
| CVE-2020-28212 | CRITICAL | 9.8 | 2.6% | Nov 19, 2020 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxur... |
| CVE-2020-28211 | HIGH | 7.8 | 0.3% | Nov 19, 2020 | A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) ... |
| CVE-2020-28209 | HIGH | 7 | 0.3% | Nov 19, 2020 | A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installe... |
| CVE-2020-28350 | MEDIUM | 6.1 | 0.7% | Nov 19, 2020 | A Cross Site Scripting (XSS) vulnerability exists in OPAC in Sokrates SOWA SowaSQL through 5.6.1 via the sowacgi.php typ... |
| CVE-2020-28210 | MEDIUM | 6.1 | 0.9% | Nov 19, 2020 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoS... |
| CVE-2020-25989 | HIGH | 7.8 | 0.7% | Nov 19, 2020 | Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exp... |
| CVE-2020-28924 | HIGH | 7.5 | 1.3% | Nov 19, 2020 | An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generato... |
| CVE-2020-28951 | CRITICAL | 9.8 | 1.7% | Nov 19, 2020 | libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package nam... |
| CVE-2020-28949 | HIGH | 7.8 | 84.6% | Nov 19, 2020 | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper... |
| CVE-2020-28948 | HIGH | 7.8 | 47.5% | Nov 19, 2020 | Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. |
| CVE-2020-28941 | MEDIUM | 5.5 | 0.3% | Nov 19, 2020 | An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers ... |
| CVE-2020-28947 | MEDIUM | 6.1 | 0.8% | Nov 19, 2020 | In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled. |
| CVE-2020-22394 | MEDIUM | 6.1 | 0.7% | Nov 19, 2020 | In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability. |
| CVE-2020-12510 | HIGH | 7.3 | 0.8% | Nov 19, 2020 | The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory... |
| CVE-2020-12496 | MEDIUM | 6.5 | 0.8% | Nov 19, 2020 | Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45... |
| CVE-2020-12495 | HIGH | 8.8 | 0.9% | Nov 19, 2020 | Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to impr... |
| CVE-2020-6879 | LOW | 3.5 | 0.7% | Nov 19, 2020 | Some ZTE devices have input verification vulnerabilities. The devices support configuring a static prefix through the we... |
| CVE-2020-28942 | MEDIUM | 4.3 | 0.4% | Nov 19, 2020 | An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protoc... |
| CVE-2020-25703 | MEDIUM | 5.3 | 1.5% | Nov 19, 2020 | The participants table download in Moodle always included user emails, but should have only done so when users' emails a... |
| CVE-2020-25702 | MEDIUM | 6.1 | 1.3% | Nov 19, 2020 | In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. Thi... |
| CVE-2020-25701 | MEDIUM | 5.3 | 1.4% | Nov 19, 2020 | If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabl... |
| CVE-2020-25700 | MEDIUM | 6.5 | 1.3% | Nov 19, 2020 | In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versi... |
| CVE-2020-25699 | HIGH | 7.5 | 1.6% | Nov 19, 2020 | In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capab... |
| CVE-2020-25698 | HIGH | 7.5 | 1.9% | Nov 19, 2020 | Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing cou... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now