2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11584MEDIUM6.1A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary Ja...
CVE-2020-11583MEDIUM6.1A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrar...
CVE-2020-5773HIGH8.8Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized wr...
CVE-2020-5772HIGH7.5Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root ...
CVE-2020-5771HIGH7.5Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root ...
CVE-2020-5770HIGH8.8Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive applic...
CVE-2020-16116LOW3.3In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory vi...
CVE-2020-8575MEDIUM4.4Active IQ Unified Manager for VMware vSphere and Windows versions prior to 9.5 are susceptible to a vulnerability which ...
CVE-2020-8574HIGH7.8Active IQ Unified Manager for Linux versions prior to 9.6 ship with the Java Management Extension Remote Method Invocati...
CVE-2020-16272CRITICAL9.1The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, w...
CVE-2020-16271CRITICAL9.1The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows re...
CVE-2020-16131MEDIUM6.1Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
CVE-2020-14319MEDIUM5.9It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in ca...
CVE-2020-13820MEDIUM6.1Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
CVE-2020-12739MEDIUM5.3A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remot...
CVE-2020-16269MEDIUM5.5radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwa...
CVE-2020-4560MEDIUM6.1IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2020-4554HIGH7.8IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by ...
CVE-2020-4553HIGH7.8IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by ...
CVE-2020-4552HIGH7.8IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory c...
CVE-2020-4551HIGH7.8IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by ...
CVE-2020-4550HIGH7.8IBM i2 Analyst Notebook 9.2.1 and 9.2.2 could allow a local attacker to execute arbitrary code on the system, caused by ...
CVE-2020-4549HIGH7.8IBM i2 Analyst Notebook 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory c...
CVE-2020-4534HIGH8.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated priv...
CVE-2020-4377CRITICAL9.1IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML dat...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now