2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3143HIGH7.2A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TeleP...
CVE-2020-3137MEDIUM6.1A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthentic...
CVE-2020-3135HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unaut...
CVE-2020-3133HIGH7.5A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a...
CVE-2020-3130MEDIUM6.5A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker t...
CVE-2020-3124MEDIUM6.5A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an un...
CVE-2020-3117MEDIUM4.7A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security ...
CVE-2020-3116MEDIUM5.5A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an a...
CVE-2020-25515HIGH7.8Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<s...
CVE-2020-25514HIGH8.4Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://...
CVE-2020-15839MEDIUM6.5Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the siz...
CVE-2020-14031HIGH7.2An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be u...
CVE-2020-14028HIGH7.2An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Auto...
CVE-2020-14027MEDIUM5.3An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arg...
CVE-2020-14026HIGH8.8CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS ...
CVE-2020-14025HIGH8.8Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a lin...
CVE-2020-14024MEDIUM6.1Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) R...
CVE-2020-14023MEDIUM4.9Ozeki NG SMS Gateway through 4.17.6 allows SSRF via SMS WCF or RSS To SMS.
CVE-2020-14022HIGH8.8Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contac...
CVE-2020-25487HIGH7.8PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php...
CVE-2020-24333MEDIUM6.5A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rig...
CVE-2020-16202HIGH7.8WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, whic...
CVE-2020-11856CRITICAL9.8Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. Th...
CVE-2020-4622HIGH7.5IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it us...
CVE-2020-4621HIGH8.8IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now