2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4644MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the vi...
CVE-2020-4574HIGH7.5IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it eas...
CVE-2020-4573MEDIUM5.3IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated...
CVE-2020-4572MEDIUM5.3IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a deta...
CVE-2020-4569MEDIUM6.5IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an ...
CVE-2020-4567CRITICAL9.8IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote atta...
CVE-2020-4463HIGH8.2IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when proc...
CVE-2020-2078MEDIUM6.5Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1...
CVE-2020-2077HIGH7.5SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions ...
CVE-2020-2076CRITICAL9.8SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by direct...
CVE-2020-14488HIGH8.8OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to uplo...
CVE-2020-14487CRITICAL9.8OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly ...
CVE-2020-14486HIGH8.8An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of...
CVE-2020-9692MEDIUM6.5Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Success...
CVE-2020-9691CRITICAL9.6Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Suc...
CVE-2020-9690MEDIUM4.2Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Suc...
CVE-2020-9689MEDIUM6.5Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploita...
CVE-2020-7698CRITICAL9.8This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endp...
CVE-2020-7697CRITICAL9.8This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affec...
CVE-2020-14493HIGH8.8A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which...
CVE-2020-14492MEDIUM6.1OpenClinic GA 5.09.02 and 5.89.05b does not properly neutralize user-controllable input, which may allow the execution o...
CVE-2020-14490HIGH8.8OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files...
CVE-2020-14489HIGH7.5OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to ...
CVE-2020-5614MEDIUM5.3Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unsp...
CVE-2020-5613MEDIUM6.1Cross-site scripting vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to execute an arbitrary script ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now