2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15223 | HIGH | 8 | 1.6% | Sep 24, 2020 | In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationH... |
| CVE-2020-15222 | HIGH | 8.1 | 0.9% | Sep 24, 2020 | In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_k... |
| CVE-2020-13119 | HIGH | 8.1 | 0.8% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to clickjacking. |
| CVE-2020-12843 | CRITICAL | 9.8 | 1.3% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magi... |
| CVE-2020-12842 | CRITICAL | 9.8 | 1.5% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php. |
| CVE-2020-12841 | MEDIUM | 6.5 | 0.5% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php |
| CVE-2020-12840 | MEDIUM | 6.5 | 0.5% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php |
| CVE-2020-12839 | CRITICAL | 9.8 | 1.5% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php. |
| CVE-2020-12838 | CRITICAL | 9.8 | 1.5% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php. |
| CVE-2020-12837 | HIGH | 7.5 | 0.9% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magi... |
| CVE-2020-12282 | HIGH | 8.8 | 0.5% | Sep 24, 2020 | iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible ... |
| CVE-2020-12281 | MEDIUM | 6.5 | 0.5% | Sep 24, 2020 | iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php. |
| CVE-2020-6153 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-26088 | MEDIUM | 5.5 | 0.4% | Sep 24, 2020 | A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used b... |
| CVE-2020-24365 | HIGH | 8.8 | 11.4% | Sep 24, 2020 | An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic n... |
| CVE-2020-15840 | MEDIUM | 5.3 | 1.0% | Sep 24, 2020 | In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.r... |
| CVE-2020-13521 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-13508 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-13507 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-13505 | CRITICAL | 9.8 | 1.2% | Sep 24, 2020 | Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP w... |
| CVE-2020-13504 | CRITICAL | 9.8 | 1.2% | Sep 24, 2020 | Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted... |
| CVE-2020-13503 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-13502 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-13501 | CRITICAL | 9.8 | 2.9% | Sep 24, 2020 | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1... |
| CVE-2020-13500 | CRITICAL | 9.8 | 2.9% | Sep 24, 2020 | SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now