2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15011MEDIUM4.3GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
CVE-2020-15007CRITICAL9.8A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execut...
CVE-2020-15006MEDIUM5.4Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
CVE-2020-10280HIGH7.5The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, eff...
CVE-2020-10279CRITICAL9.8MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop us...
CVE-2020-10278MEDIUM4.6The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings suc...
CVE-2020-10277MEDIUM6.4There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of se...
CVE-2020-10276CRITICAL9.8The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated progr...
CVE-2020-10275CRITICAL9.8The access tokens for the REST API are directly derived from the publicly available default credentials for the web inte...
CVE-2020-10274HIGH7.1The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default...
CVE-2020-10273HIGH7.5MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual proper...
CVE-2020-10272CRITICAL9.8MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra...
CVE-2020-10271CRITICAL9.8MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra...
CVE-2020-10270CRITICAL9.8Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to a...
CVE-2020-10269CRITICAL9.8One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles com...
CVE-2020-9480CRITICAL9.8In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (s...
CVE-2020-12033HIGH8.8In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not ...
CVE-2020-12021CRITICAL9In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cros...
CVE-2020-5367HIGH8.1Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p...
CVE-2020-5345MEDIUM5.4Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p...
CVE-2020-14978HIGH8.1An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can co...
CVE-2020-14977HIGH8.1An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, ...
CVE-2020-14976MEDIUM5.5GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary fi...
CVE-2020-14975HIGH7.8The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code ...
CVE-2020-14974HIGH7.1The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now