2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10287CRITICAL9.8The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manua...
CVE-2020-15780MEDIUM6.7An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI ta...
CVE-2020-15107MEDIUM5.3In openenclave before 0.10.0, enclaves that use x87 FPU operations are vulnerable to tampering by a malicious host appli...
CVE-2020-10286HIGH8.8the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to p...
CVE-2020-9311MEDIUM5.4In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile ...
CVE-2020-9309HIGH8.8Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file ex...
CVE-2020-8958HIGH7.2Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow...
CVE-2020-6165MEDIUM5.3SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This aff...
CVE-2020-6164HIGH7.5In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can b...
CVE-2020-15779HIGH7.5A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::crea...
CVE-2020-15051MEDIUM6.1An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Add...
CVE-2020-14982MEDIUM6.5A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352prem...
CVE-2020-13788MEDIUM4.3Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of ...
CVE-2020-10285CRITICAL9.8The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force att...
CVE-2020-15718MEDIUM6.1RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php sc...
CVE-2020-15603HIGH7.5An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products'...
CVE-2020-15602HIGH7.8An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and bel...
CVE-2020-15366MEDIUM5.6An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON sc...
CVE-2020-14066HIGH8.8IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to acces...
CVE-2020-14065MEDIUM6.5IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.
CVE-2020-14064MEDIUM6.5IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.
CVE-2020-12854HIGH8.8A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can ...
CVE-2020-12684CRITICAL9.8XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, w...
CVE-2020-11439HIGH8.8LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed wi...
CVE-2020-11438HIGH8.8LibreHealth EMR v2.0.0 is affected by systemic CSRF.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now