2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15011 | MEDIUM | 4.3 | 1.9% | Jun 24, 2020 | GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. |
| CVE-2020-15007 | CRITICAL | 9.8 | 2.3% | Jun 24, 2020 | A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execut... |
| CVE-2020-15006 | MEDIUM | 5.4 | 0.5% | Jun 24, 2020 | Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php. |
| CVE-2020-10280 | HIGH | 7.5 | 1.2% | Jun 24, 2020 | The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, eff... |
| CVE-2020-10279 | CRITICAL | 9.8 | 1.0% | Jun 24, 2020 | MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop us... |
| CVE-2020-10278 | MEDIUM | 4.6 | 1.0% | Jun 24, 2020 | The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings suc... |
| CVE-2020-10277 | MEDIUM | 6.4 | 0.4% | Jun 24, 2020 | There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of se... |
| CVE-2020-10276 | CRITICAL | 9.8 | 1.5% | Jun 24, 2020 | The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated progr... |
| CVE-2020-10275 | CRITICAL | 9.8 | 1.0% | Jun 24, 2020 | The access tokens for the REST API are directly derived from the publicly available default credentials for the web inte... |
| CVE-2020-10274 | HIGH | 7.1 | 0.9% | Jun 24, 2020 | The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default... |
| CVE-2020-10273 | HIGH | 7.5 | 0.9% | Jun 24, 2020 | MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual proper... |
| CVE-2020-10272 | CRITICAL | 9.8 | 2.5% | Jun 24, 2020 | MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra... |
| CVE-2020-10271 | CRITICAL | 9.8 | 1.8% | Jun 24, 2020 | MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational gra... |
| CVE-2020-10270 | CRITICAL | 9.8 | 1.7% | Jun 24, 2020 | Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to a... |
| CVE-2020-10269 | CRITICAL | 9.8 | 1.4% | Jun 24, 2020 | One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles com... |
| CVE-2020-9480 | CRITICAL | 9.8 | 29.2% | Jun 23, 2020 | In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (s... |
| CVE-2020-12033 | HIGH | 8.8 | 1.1% | Jun 23, 2020 | In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not ... |
| CVE-2020-12021 | CRITICAL | 9 | 1.6% | Jun 23, 2020 | In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cros... |
| CVE-2020-5367 | HIGH | 8.1 | 0.6% | Jun 23, 2020 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p... |
| CVE-2020-5345 | MEDIUM | 5.4 | 0.7% | Jun 23, 2020 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions p... |
| CVE-2020-14978 | HIGH | 8.1 | 3.1% | Jun 23, 2020 | An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can co... |
| CVE-2020-14977 | HIGH | 8.1 | 2.8% | Jun 23, 2020 | An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, ... |
| CVE-2020-14976 | MEDIUM | 5.5 | 0.5% | Jun 23, 2020 | GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary fi... |
| CVE-2020-14975 | HIGH | 7.8 | 0.6% | Jun 23, 2020 | The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code ... |
| CVE-2020-14974 | HIGH | 7.1 | 0.9% | Jun 23, 2020 | The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now