2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4644 | MEDIUM | 5.4 | 1.2% | Jul 29, 2020 | IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the vi... |
| CVE-2020-4574 | HIGH | 7.5 | 1.9% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it eas... |
| CVE-2020-4573 | MEDIUM | 5.3 | 1.3% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated... |
| CVE-2020-4572 | MEDIUM | 5.3 | 1.7% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a deta... |
| CVE-2020-4569 | MEDIUM | 6.5 | 1.2% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an ... |
| CVE-2020-4567 | CRITICAL | 9.8 | 2.3% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote atta... |
| CVE-2020-4463 | HIGH | 8.2 | 31.6% | Jul 29, 2020 | IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when proc... |
| CVE-2020-2078 | MEDIUM | 6.5 | 0.8% | Jul 29, 2020 | Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1... |
| CVE-2020-2077 | HIGH | 7.5 | 1.0% | Jul 29, 2020 | SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions ... |
| CVE-2020-2076 | CRITICAL | 9.8 | 1.3% | Jul 29, 2020 | SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by direct... |
| CVE-2020-14488 | HIGH | 8.8 | 1.7% | Jul 29, 2020 | OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to uplo... |
| CVE-2020-14487 | CRITICAL | 9.8 | 2.2% | Jul 29, 2020 | OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly ... |
| CVE-2020-14486 | HIGH | 8.8 | 1.3% | Jul 29, 2020 | An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of... |
| CVE-2020-9692 | MEDIUM | 6.5 | 3.8% | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Success... |
| CVE-2020-9691 | CRITICAL | 9.6 | 6.0% | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Suc... |
| CVE-2020-9690 | MEDIUM | 4.2 | 1.6% | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Suc... |
| CVE-2020-9689 | MEDIUM | 6.5 | 4.1% | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploita... |
| CVE-2020-7698 | CRITICAL | 9.8 | 1.7% | Jul 29, 2020 | This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endp... |
| CVE-2020-7697 | CRITICAL | 9.8 | 2.0% | Jul 29, 2020 | This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affec... |
| CVE-2020-14493 | HIGH | 8.8 | 1.7% | Jul 29, 2020 | A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which... |
| CVE-2020-14492 | MEDIUM | 6.1 | 1.2% | Jul 29, 2020 | OpenClinic GA 5.09.02 and 5.89.05b does not properly neutralize user-controllable input, which may allow the execution o... |
| CVE-2020-14490 | HIGH | 8.8 | 2.5% | Jul 29, 2020 | OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files... |
| CVE-2020-14489 | HIGH | 7.5 | 1.0% | Jul 29, 2020 | OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to ... |
| CVE-2020-5614 | MEDIUM | 5.3 | 2.2% | Jul 29, 2020 | Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unsp... |
| CVE-2020-5613 | MEDIUM | 6.1 | 1.1% | Jul 29, 2020 | Cross-site scripting vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to execute an arbitrary script ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now