2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13958HIGH7.8A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks po...
CVE-2020-27558MEDIUM6.5Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video st...
CVE-2020-27557MEDIUM5.5Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to g...
CVE-2020-27556MEDIUM5.3A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to conne...
CVE-2020-27555CRITICAL9.8Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers...
CVE-2020-27554HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists whi...
CVE-2020-27553HIGH7.5In BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoo...
CVE-2020-25798MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users w...
CVE-2020-21665HIGH7.2In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be pas...
CVE-2020-7841HIGH8.8Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution whe...
CVE-2020-28688HIGH8.8The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo...
CVE-2020-28687HIGH8.8The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upl...
CVE-2020-28647MEDIUM5.4In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a...
CVE-2020-25746MEDIUM4.6QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obta...
CVE-2020-7774CRITICAL9.8The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
CVE-2020-27131CRITICAL9.8Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unau...
CVE-2020-27130CRITICAL9.1A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive in...
CVE-2020-27125CRITICAL9.8A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive informatio...
CVE-2020-27192HIGH7.8BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allo...
CVE-2020-25833MEDIUM4.8Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. ...
CVE-2020-25832MEDIUM5.4Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability cou...
CVE-2020-25705HIGH7.4A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off...
CVE-2020-15349HIGH7.8BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool i...
CVE-2020-14389HIGH8.1It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources...
CVE-2020-11851CRITICAL9.8Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now