2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13499 | CRITICAL | 9.8 | 2.9% | Sep 24, 2020 | An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1... |
| CVE-2020-12818 | MEDIUM | 5.3 | 0.9% | Sep 24, 2020 | An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker t... |
| CVE-2020-12817 | HIGH | 8.8 | 2.3% | Sep 24, 2020 | An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticat... |
| CVE-2020-12816 | MEDIUM | 6.1 | 1.2% | Sep 24, 2020 | An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to ... |
| CVE-2020-12280 | MEDIUM | 6.5 | 0.5% | Sep 24, 2020 | iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /... |
| CVE-2020-6020 | MEDIUM | 6.4 | 0.5% | Sep 24, 2020 | Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 ... |
| CVE-2020-22453 | MEDIUM | 6.1 | 0.7% | Sep 24, 2020 | Untis WebUntis before 2020.9.6 allows XSS in multiple functions that store information. |
| CVE-2020-16148 | HIGH | 7.2 | 1.9% | Sep 24, 2020 | The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell... |
| CVE-2020-16147 | CRITICAL | 9.8 | 2.0% | Sep 24, 2020 | The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated... |
| CVE-2020-24560 | HIGH | 7.5 | 1.8% | Sep 24, 2020 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o... |
| CVE-2020-15604 | HIGH | 7.5 | 1.6% | Sep 24, 2020 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o... |
| CVE-2020-25604 | MEDIUM | 4.7 | 0.3% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. Wh... |
| CVE-2020-25603 | HIGH | 7.8 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event chan... |
| CVE-2020-25602 | MEDIUM | 6 | 0.3% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to... |
| CVE-2020-25601 | MEDIUM | 5.5 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In pa... |
| CVE-2020-25600 | MEDIUM | 5.5 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so ... |
| CVE-2020-25599 | HIGH | 7 | 0.3% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potenti... |
| CVE-2020-25598 | MEDIUM | 5.5 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Rea... |
| CVE-2020-25597 | MEDIUM | 6.5 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may... |
| CVE-2020-25596 | MEDIUM | 5.5 | 0.5% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The S... |
| CVE-2020-25595 | HIGH | 7.8 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen... |
| CVE-2020-5783 | MEDIUM | 5.4 | 0.4% | Sep 23, 2020 | In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms. |
| CVE-2020-5782 | MEDIUM | 6.5 | 1.0% | Sep 23, 2020 | In IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the d... |
| CVE-2020-5781 | MEDIUM | 4.3 | 0.9% | Sep 23, 2020 | In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/confi... |
| CVE-2020-11031 | HIGH | 7.5 | 0.3% | Sep 23, 2020 | In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now