2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11083MEDIUM4.8In October from version 1.0.319 and before version 1.0.466, a user with access to a markdown FormWidget that stores data...
CVE-2020-9297CRITICAL9.8Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint valida...
CVE-2020-5374HIGH7.5Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain...
CVE-2020-5373HIGH7.5Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain...
CVE-2020-15100LOW3.3In freewvs before 0.1.1, a user could create a large file that freewvs will try to read, which will terminate a scan pro...
CVE-2020-11546CRITICAL9.8SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailing...
CVE-2020-15074HIGH7.5OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reu...
CVE-2020-13847HIGH7.5Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not s...
CVE-2020-13846HIGH7.5Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
CVE-2020-13845HIGH7.5Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated...
CVE-2020-11827HIGH7.8In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. A...
CVE-2020-15721MEDIUM6.1RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.p...
CVE-2020-13935HIGH7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to...
CVE-2020-13934HIGH7.5An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release...
CVE-2020-7593CRITICAL9.8A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLU...
CVE-2020-7592MEDIUM6.5A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), S...
CVE-2020-7588MEDIUM5.3A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation ...
CVE-2020-7587HIGH8.2A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation ...
CVE-2020-7584HIGH7.5A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices...
CVE-2020-7581MEDIUM6.7A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation ...
CVE-2020-7578HIGH8.1A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions...
CVE-2020-7577HIGH8.1A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions...
CVE-2020-7576MEDIUM5.4A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions...
CVE-2020-1948CRITICAL9.8This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unr...
CVE-2020-15720MEDIUM6.8In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now