2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-16847MEDIUM6.1Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in ...
CVE-2020-15135HIGH7.6save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Token...
CVE-2020-16843MEDIUM5.9In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. ...
CVE-2020-15956HIGH7.5ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer...
CVE-2020-15944MEDIUM5.4An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is ...
CVE-2020-15943HIGH8.1An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possibl...
CVE-2020-13522HIGH7.1An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially craf...
CVE-2020-16203HIGH7.8Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited ...
CVE-2020-16201LOW3.3Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilitie...
CVE-2020-16199HIGH7.8Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulne...
CVE-2020-16134HIGH8An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet...
CVE-2020-13523LOW3.3An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially c...
CVE-2020-4631MEDIUM5.5IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned acce...
CVE-2020-4542MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4525MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-4459CRITICAL9.8IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses ...
CVE-2020-4410MEDIUM4.3IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET ...
CVE-2020-4396MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2020-7823HIGH7.8DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandle...
CVE-2020-7822HIGH7.8DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishand...
CVE-2020-6012HIGH7.4ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sop...
CVE-2020-15467HIGH8.8The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticat...
CVE-2020-5617HIGH7.8Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unaut...
CVE-2020-5616CRITICAL9.8[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Cale...
CVE-2020-5615HIGH8.8Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now