2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25987HIGH7.5MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is b...
CVE-2020-25986MEDIUM6.5A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.
CVE-2020-25613HIGH7.5An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP serv...
CVE-2020-24215CRITICAL9.8An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use har...
CVE-2020-24214CRITICAL9.8An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a ...
CVE-2020-23832MEDIUM6.1A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System...
CVE-2020-5634HIGH8.8ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-17...
CVE-2020-5632HIGH7.8InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revisi...
CVE-2020-5631MEDIUM6.1Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arb...
CVE-2020-26572MEDIUM5.5The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
CVE-2020-26571MEDIUM5.5The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu...
CVE-2020-26570MEDIUM5.5The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read...
CVE-2020-15237MEDIUM5.9In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a tim...
CVE-2020-16226CRITICAL9.8Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, whic...
CVE-2020-24231CRITICAL9.8Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all...
CVE-2020-15235HIGH7.5In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would norm...
CVE-2020-6875CRITICAL9.8A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mech...
CVE-2020-26048HIGH8.8The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within...
CVE-2020-15236HIGH7.5In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with...
CVE-2020-8671MEDIUM5.5Insufficient control flow management in BIOS firmware 8th, 9th Generation Intel(R) Core(TM) Processors and Intel(R) Cele...
CVE-2020-8235MEDIUM4.3Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view a...
CVE-2020-8228MEDIUM5.3A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount...
CVE-2020-8223MEDIUM6.5A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher p...
CVE-2020-8182HIGH8Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permiss...
CVE-2020-4493CRITICAL9.8IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now