2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7511 | HIGH | 7.5 | 0.9% | Jun 16, 2020 | A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy T300 (Firmware version 1.5.2... |
| CVE-2020-7510 | HIGH | 7.5 | 1.4% | Jun 16, 2020 | A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allo... |
| CVE-2020-7509 | HIGH | 7.2 | 1.2% | Jun 16, 2020 | A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older)... |
| CVE-2020-7508 | CRITICAL | 9.8 | 1.4% | Jun 16, 2020 | A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware versi... |
| CVE-2020-7507 | HIGH | 7.5 | 1.3% | Jun 16, 2020 | A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) whi... |
| CVE-2020-7506 | HIGH | 7.5 | 1.3% | Jun 16, 2020 | A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an at... |
| CVE-2020-7505 | HIGH | 7.2 | 0.9% | Jun 16, 2020 | A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and olde... |
| CVE-2020-7504 | MEDIUM | 5.3 | 1.3% | Jun 16, 2020 | A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could ... |
| CVE-2020-7503 | HIGH | 8.8 | 0.6% | Jun 16, 2020 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) whi... |
| CVE-2020-7502 | HIGH | 7.5 | 1.5% | Jun 16, 2020 | A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), w... |
| CVE-2020-7501 | HIGH | 8.8 | 1.1% | Jun 16, 2020 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vij... |
| CVE-2020-7500 | CRITICAL | 9.8 | 1.9% | Jun 16, 2020 | A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.... |
| CVE-2020-7499 | MEDIUM | 6.5 | 0.8% | Jun 16, 2020 | A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed i... |
| CVE-2020-7498 | CRITICAL | 9.8 | 1.4% | Jun 16, 2020 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions).... |
| CVE-2020-7497 | CRITICAL | 9.8 | 2.3% | Jun 16, 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStru... |
| CVE-2020-7496 | HIGH | 7.8 | 0.9% | Jun 16, 2020 | A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pa... |
| CVE-2020-7495 | MEDIUM | 5.5 | 0.9% | Jun 16, 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file e... |
| CVE-2020-7494 | HIGH | 7.8 | 1.3% | Jun 16, 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStru... |
| CVE-2020-7493 | HIGH | 7.8 | 1.1% | Jun 16, 2020 | A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in E... |
| CVE-2020-7492 | MEDIUM | 6.5 | 1.1% | Jun 16, 2020 | A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the dis... |
| CVE-2020-13162 | HIGH | 7 | 0.8% | Jun 16, 2020 | A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down ... |
| CVE-2020-14199 | MEDIUM | 6.5 | 0.8% | Jun 16, 2020 | BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to ... |
| CVE-2020-10268 | MEDIUM | 6.1 | 0.3% | Jun 16, 2020 | Critical services for operation can be terminated from windows task manager, bringing the manipulator to a halt. After t... |
| CVE-2020-14195 | HIGH | 8.1 | 4.5% | Jun 16, 2020 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-9522 | MEDIUM | 6.1 | 0.6% | Jun 16, 2020 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting ve... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now