2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-17385HIGH7.5Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to lau...
CVE-2020-17384HIGH7.2Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system adminis...
CVE-2020-5620MEDIUM5.4Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary s...
CVE-2020-5619MEDIUM5.4Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary s...
CVE-2020-5541MEDIUM6.1Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary site...
CVE-2020-5540MEDIUM6.1Cross-site scripting vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to inject arbitrary script o...
CVE-2020-24613MEDIUM6.8wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in t...
CVE-2020-24612MEDIUM4.7An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config...
CVE-2020-24572HIGH8.8An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misco...
CVE-2020-7377HIGH7.5The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path tr...
CVE-2020-7376CRITICAL9.8The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability...
CVE-2020-6637CRITICAL9.8openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
CVE-2020-24364HIGH8.8MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meetin...
CVE-2020-7705HIGH8.1This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality ...
CVE-2020-24606HIGH7.5Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU...
CVE-2020-10775MEDIUM5.3An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to r...
CVE-2020-4598MEDIUM6.1IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect a...
CVE-2020-4593MEDIUM4.4IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. I...
CVE-2020-4587HIGH7.8IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caus...
CVE-2020-4383MEDIUM6.5IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denia...
CVE-2020-4382MEDIUM5.5IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denia...
CVE-2020-4170MEDIUM4.3IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execut...
CVE-2020-4165MEDIUM5.4IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persu...
CVE-2020-14044HIGH7.2** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 ...
CVE-2020-14043HIGH8.8** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now