2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15276HIGH8.7baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a ...
CVE-2020-15273HIGH8.1baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit fe...
CVE-2020-15277HIGH7.2baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system...
CVE-2020-7373CRITICAL9.8vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe...
CVE-2020-4588HIGH7.8IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting...
CVE-2020-4584HIGH7.5IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error messag...
CVE-2020-7760HIGH7.5This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The...
CVE-2020-7759HIGH7.2The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functiona...
CVE-2020-27015MEDIUM4.4Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exp...
CVE-2020-27014MEDIUM6.4Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Block...
CVE-2020-27885MEDIUM6.1Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability t...
CVE-2020-26205MEDIUM5.4Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal throug...
CVE-2020-25646HIGH7.5A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This direc...
CVE-2020-14323MEDIUM5.5A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and befor...
CVE-2020-27887HIGH8.8An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could a...
CVE-2020-27886CRITICAL9.8An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injectio...
CVE-2020-27998CRITICAL9.8An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (fo...
CVE-2020-27996HIGH8.8An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttri...
CVE-2020-27747MEDIUM6.8An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a...
CVE-2020-27995CRITICAL9.8SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the se...
CVE-2020-27744CRITICAL9.8An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with r...
CVE-2020-25780HIGH7.5In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, D...
CVE-2020-5936HIGH7.5On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel...
CVE-2020-5935MEDIUM5.9On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14....
CVE-2020-5934MEDIUM6.5On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now