2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13499CRITICAL9.8An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1...
CVE-2020-12818MEDIUM5.3An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker t...
CVE-2020-12817HIGH8.8An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticat...
CVE-2020-12816MEDIUM6.1An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to ...
CVE-2020-12280MEDIUM6.5iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /...
CVE-2020-6020MEDIUM6.4Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 ...
CVE-2020-22453MEDIUM6.1Untis WebUntis before 2020.9.6 allows XSS in multiple functions that store information.
CVE-2020-16148HIGH7.2The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell...
CVE-2020-16147CRITICAL9.8The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated...
CVE-2020-24560HIGH7.5An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o...
CVE-2020-15604HIGH7.5An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o...
CVE-2020-25604MEDIUM4.7An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. Wh...
CVE-2020-25603HIGH7.8An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event chan...
CVE-2020-25602MEDIUM6An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to...
CVE-2020-25601MEDIUM5.5An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In pa...
CVE-2020-25600MEDIUM5.5An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so ...
CVE-2020-25599HIGH7An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potenti...
CVE-2020-25598MEDIUM5.5An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Rea...
CVE-2020-25597MEDIUM6.5An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may...
CVE-2020-25596MEDIUM5.5An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The S...
CVE-2020-25595HIGH7.8An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen...
CVE-2020-5783MEDIUM5.4In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.
CVE-2020-5782MEDIUM6.5In IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the d...
CVE-2020-5781MEDIUM4.3In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/confi...
CVE-2020-11031HIGH7.5In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on th...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now