2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4405MEDIUM4.3IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due t...
CVE-2020-15593HIGH7.8SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Win...
CVE-2020-15592HIGH7.5SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an exec...
CVE-2020-9251LOW2.4HUAWEI Mate 20 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have an improper authorization vulnerabil...
CVE-2020-9077LOW3.3HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. ...
CVE-2020-11110MEDIUM5.4Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an a...
CVE-2020-7695MEDIUM5.3Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP head...
CVE-2020-7694HIGH7.5This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape se...
CVE-2020-5611HIGH8.8Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attacker...
CVE-2020-15954MEDIUM6.5KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encrypt...
CVE-2020-15953HIGH7.4LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affe...
CVE-2020-7687HIGH7.5This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in ind...
CVE-2020-7686HIGH7.5This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation insid...
CVE-2020-7683HIGH7.5This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed...
CVE-2020-7682HIGH7.5This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in i...
CVE-2020-7681HIGH7.5This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in inde...
CVE-2020-10614MEDIUM4.8In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision dat...
CVE-2020-10604HIGH7.5In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager s...
CVE-2020-12812CRITICAL9.8An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a us...
CVE-2020-10610HIGH7.8In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exp...
CVE-2020-10608HIGH7.8In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity che...
CVE-2020-10606HIGH7.8In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected ...
CVE-2020-10602MEDIUM5.3In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due...
CVE-2020-10600HIGH7.1An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. T...
CVE-2020-8207HIGH8.8Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code exe...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now