2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-17494MEDIUM5.3Untangle Firewall NG before 16.0 uses MD5 for passwords.
CVE-2020-13877CRITICAL9.8SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and...
CVE-2020-28415MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauth...
CVE-2020-28414MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauth...
CVE-2020-15783HIGH7.5A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All ver...
CVE-2020-13774CRITICAL9.9An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an aut...
CVE-2020-12927HIGH7.8A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated use...
CVE-2020-12926MEDIUM6.4The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happe...
CVE-2020-12912MEDIUM5.5A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Run...
CVE-2020-8669MEDIUM6.5Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us...
CVE-2020-27386HIGH8.8An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and e...
CVE-2020-27385HIGH8.1Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenti...
CVE-2020-26805HIGH7.2In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetai...
CVE-2020-26804HIGH8.8In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users ...
CVE-2020-26803HIGH8.8In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered f...
CVE-2020-24525HIGH7.8Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potenti...
CVE-2020-24460MEDIUM5.5Incorrect default permissions in the Intel(R) DSA before version 20.8.30.6 may allow an authenticated user to potentiall...
CVE-2020-24456HIGH7.8Incorrect default permissions in the Intel(R) Board ID Tool version v.1.01 may allow an authenticated user to potentiall...
CVE-2020-24454HIGH7.5Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before versi...
CVE-2020-16273HIGH7.8In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by...
CVE-2020-12353MEDIUM6.5Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to...
CVE-2020-12350HIGH7.8Improper access control in the Intel(R) XTU before version 6.5.1.360 may allow an authenticated user to potentially enab...
CVE-2020-12349MEDIUM6.5Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us...
CVE-2020-12347HIGH8.8Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us...
CVE-2020-12346HIGH7.8Improper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an au...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now