2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7514HIGH7.8A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and...
CVE-2020-7491HIGH7.5**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 t...
CVE-2020-15633HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86...
CVE-2020-15632HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-84...
CVE-2020-15631HIGH8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1...
CVE-2020-11625MEDIUM5.3An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Ind...
CVE-2020-11624CRITICAL9.8An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Ind...
CVE-2020-15492CRITICAL9.8An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we...
CVE-2020-15477CRITICAL9.8The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters i...
CVE-2020-15391CRITICAL9.8The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authe...
CVE-2020-11623MEDIUM6.8An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Ind...
CVE-2020-15917CRITICAL9.8common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
CVE-2020-15916CRITICAL9.8goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system...
CVE-2020-8557MEDIUM5.5The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage ...
CVE-2020-4447MEDIUM5.4IBM FileNet Content Manager 5.5.3 and 5.5.4 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2020-12638MEDIUM6.8An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3....
CVE-2020-10922HIGH7.5This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE H...
CVE-2020-10921CRITICAL9.8This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware versio...
CVE-2020-10920CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmwar...
CVE-2020-10919MEDIUM5.9This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9...
CVE-2020-10918HIGH7.5This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware...
CVE-2020-15912MEDIUM6.5Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC ...
CVE-2020-15887HIGH8.8A SQL injection vulnerability in softwareupdate_controller.php in the Software Update module before 1.6 for MunkiReport ...
CVE-2020-15886HIGH8.8A SQL injection vulnerability in reportdata_controller.php in the reportdata module before 3.5 for MunkiReport allows at...
CVE-2020-15885MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to i...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now