2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13913MEDIUM6.1An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript...
CVE-2020-15715CRITICAL9.9rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error i...
CVE-2020-15714HIGH8.8rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the d...
CVE-2020-15713HIGH8.8rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the d...
CVE-2020-15712MEDIUM4.3rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send ...
CVE-2020-4465MEDIUM6.5IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnera...
CVE-2020-4375HIGH7.5IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of s...
CVE-2020-4319MEDIUM4.3IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, a...
CVE-2020-4318MEDIUM5.4IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operation...
CVE-2020-4317MEDIUM5.4IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operation...
CVE-2020-16088CRITICAL9.8iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for chec...
CVE-2020-12880MEDIUM5.5An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By m...
CVE-2020-12845HIGH7.5Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticat...
CVE-2020-12460CRITICAL9.8OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse ...
CVE-2020-10643MEDIUM5.4An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vuln...
CVE-2020-8558HIGH8.8The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain ...
CVE-2020-1457HIGH7.8A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory,...
CVE-2020-1425HIGH7.8A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory...
CVE-2020-10609HIGH7.5Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modif...
CVE-2020-7017MEDIUM6.7In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who i...
CVE-2020-7016MEDIUM4.8Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a ...
CVE-2020-15120MEDIUM4.9In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another ...
CVE-2020-15103LOW3.5In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. A...
CVE-2020-4498MEDIUM4.4IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inc...
CVE-2020-4408MEDIUM4.6The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords duri...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now