2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10916HIGH8This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA85...
CVE-2020-9475HIGH7The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows local privilege escalation via a race condition in log...
CVE-2020-9474HIGH8.8The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows remote code execution via the backup functionality in ...
CVE-2020-11056MEDIUM6.3In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields...
CVE-2020-11055MEDIUM5.4In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A ...
CVE-2020-11054LOW3.5In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificat...
CVE-2020-11053MEDIUM6.1In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the prox...
CVE-2020-11052CRITICAL9.8In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute...
CVE-2020-11050HIGH8.1In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where W...
CVE-2020-10795HIGH7.2Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web...
CVE-2020-10794CRITICAL9.8Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the appl...
CVE-2020-10176CRITICAL9.8ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.
CVE-2020-4430MEDIUM4.3IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories...
CVE-2020-4429CRITICAL9.8IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ...
CVE-2020-4428CRITICAL9.1IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary co...
CVE-2020-4427CRITICAL9.8IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest...
CVE-2020-12708MEDIUM6.1Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web scrip...
CVE-2020-12707MEDIUM6.1An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only secur...
CVE-2020-12706MEDIUM5.4Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web scrip...
CVE-2020-12705MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
CVE-2020-12704MEDIUM6.1UliCMS before 2020.2 has PageController stored XSS.
CVE-2020-12703MEDIUM6.1UliCMS before 2020.2 has XSS during PackageController uninstall.
CVE-2020-12116HIGH7.5Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attack...
CVE-2020-11049LOW2.2In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the prot...
CVE-2020-11048LOW2.2In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extrac...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now