2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17494 | MEDIUM | 5.3 | 0.8% | Nov 12, 2020 | Untangle Firewall NG before 16.0 uses MD5 for passwords. |
| CVE-2020-13877 | CRITICAL | 9.8 | 2.1% | Nov 12, 2020 | SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and... |
| CVE-2020-28415 | MEDIUM | 6.1 | 1.1% | Nov 12, 2020 | A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauth... |
| CVE-2020-28414 | MEDIUM | 6.1 | 1.1% | Nov 12, 2020 | A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauth... |
| CVE-2020-15783 | HIGH | 7.5 | 1.6% | Nov 12, 2020 | A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All ver... |
| CVE-2020-13774 | CRITICAL | 9.9 | 4.7% | Nov 12, 2020 | An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an aut... |
| CVE-2020-12927 | HIGH | 7.8 | 0.3% | Nov 12, 2020 | A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated use... |
| CVE-2020-12926 | MEDIUM | 6.4 | 0.2% | Nov 12, 2020 | The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happe... |
| CVE-2020-12912 | MEDIUM | 5.5 | 0.5% | Nov 12, 2020 | A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Run... |
| CVE-2020-8669 | MEDIUM | 6.5 | 0.9% | Nov 12, 2020 | Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us... |
| CVE-2020-27386 | HIGH | 8.8 | 72.9% | Nov 12, 2020 | An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and e... |
| CVE-2020-27385 | HIGH | 8.1 | 1.7% | Nov 12, 2020 | Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenti... |
| CVE-2020-26805 | HIGH | 7.2 | 1.5% | Nov 12, 2020 | In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetai... |
| CVE-2020-26804 | HIGH | 8.8 | 1.4% | Nov 12, 2020 | In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users ... |
| CVE-2020-26803 | HIGH | 8.8 | 1.4% | Nov 12, 2020 | In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered f... |
| CVE-2020-24525 | HIGH | 7.8 | 0.3% | Nov 12, 2020 | Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potenti... |
| CVE-2020-24460 | MEDIUM | 5.5 | 0.2% | Nov 12, 2020 | Incorrect default permissions in the Intel(R) DSA before version 20.8.30.6 may allow an authenticated user to potentiall... |
| CVE-2020-24456 | HIGH | 7.8 | 0.3% | Nov 12, 2020 | Incorrect default permissions in the Intel(R) Board ID Tool version v.1.01 may allow an authenticated user to potentiall... |
| CVE-2020-24454 | HIGH | 7.5 | 1.2% | Nov 12, 2020 | Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before versi... |
| CVE-2020-16273 | HIGH | 7.8 | 0.3% | Nov 12, 2020 | In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by... |
| CVE-2020-12353 | MEDIUM | 6.5 | 0.8% | Nov 12, 2020 | Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to... |
| CVE-2020-12350 | HIGH | 7.8 | 0.3% | Nov 12, 2020 | Improper access control in the Intel(R) XTU before version 6.5.1.360 may allow an authenticated user to potentially enab... |
| CVE-2020-12349 | MEDIUM | 6.5 | 0.9% | Nov 12, 2020 | Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us... |
| CVE-2020-12347 | HIGH | 8.8 | 1.3% | Nov 12, 2020 | Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated us... |
| CVE-2020-12346 | HIGH | 7.8 | 0.3% | Nov 12, 2020 | Improper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an au... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now