2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15884HIGH8.8A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL co...
CVE-2020-15883MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attack...
CVE-2020-15882HIGH8.1A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines fr...
CVE-2020-15881MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the munki_facts (aka Munki Conditions) module before 1.5 for MunkiReport a...
CVE-2020-11440HIGH7.5httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.
CVE-2020-15688HIGH8.8The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks...
CVE-2020-15908HIGH7.5tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction fro...
CVE-2020-15904HIGH7.8A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond all...
CVE-2020-15126MEDIUM6.5In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass a...
CVE-2020-10917CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.4...
CVE-2020-15902MEDIUM6.1Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
CVE-2020-15901HIGH8.8In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsub...
CVE-2020-4400HIGH7.5IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker t...
CVE-2020-4399MEDIUM6.5IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial ...
CVE-2020-4397MEDIUM5.9IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an att...
CVE-2020-4385CRITICAL9.8IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which...
CVE-2020-4372HIGH7.8IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local use...
CVE-2020-4371LOW3.3IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a ...
CVE-2020-4369MEDIUM5.5IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a us...
CVE-2020-9687HIGH8.8Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exp...
CVE-2020-9686MEDIUM6.5Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful expl...
CVE-2020-9685HIGH8.8Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exp...
CVE-2020-9684HIGH8.8Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds write vulnerability. Successful exp...
CVE-2020-9683HIGH8.8Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful expl...
CVE-2020-9680HIGH8.8Adobe Prelude versions 9.0 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now