2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7511HIGH7.5A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy T300 (Firmware version 1.5.2...
CVE-2020-7510HIGH7.5A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allo...
CVE-2020-7509HIGH7.2A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older)...
CVE-2020-7508CRITICAL9.8A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware versi...
CVE-2020-7507HIGH7.5A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) whi...
CVE-2020-7506HIGH7.5A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an at...
CVE-2020-7505HIGH7.2A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and olde...
CVE-2020-7504MEDIUM5.3A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could ...
CVE-2020-7503HIGH8.8A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) whi...
CVE-2020-7502HIGH7.5A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), w...
CVE-2020-7501HIGH8.8A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vij...
CVE-2020-7500CRITICAL9.8A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U....
CVE-2020-7499MEDIUM6.5A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed i...
CVE-2020-7498CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions)....
CVE-2020-7497CRITICAL9.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStru...
CVE-2020-7496HIGH7.8A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pa...
CVE-2020-7495MEDIUM5.5A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file e...
CVE-2020-7494HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStru...
CVE-2020-7493HIGH7.8A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in E...
CVE-2020-7492MEDIUM6.5A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the dis...
CVE-2020-13162HIGH7A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down ...
CVE-2020-14199MEDIUM6.5BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to ...
CVE-2020-10268MEDIUM6.1Critical services for operation can be terminated from windows task manager, bringing the manipulator to a halt. After t...
CVE-2020-14195HIGH8.1FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, rela...
CVE-2020-9522MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting ve...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now