2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6652HIGH7.8Incorrect Privilege Assignment vulnerability in Eaton's Intelligent Power Manager (IPM) v1.67 & prior allow non-admin us...
CVE-2020-6651HIGH7.3Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration fi...
CVE-2020-12687MEDIUM6.5An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin aut...
CVE-2020-12683MEDIUM5.4Katyshop2 before 2.12 has multiple stored XSS issues.
CVE-2020-8983HIGH7.5An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, in...
CVE-2020-8982HIGH7.5An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones)...
CVE-2020-7473HIGH7.5In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most ...
CVE-2020-6081HIGH8.8An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH COD...
CVE-2020-5895HIGH7.8On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which a...
CVE-2020-5894HIGH8.1On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users lo...
CVE-2020-12696MEDIUM6.1The iframe plugin before 4.5 for WordPress does not sanitize a URL.
CVE-2020-12692MEDIUM5.4An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check ...
CVE-2020-12691HIGH8.8An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 creden...
CVE-2020-12690HIGH8.8An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access...
CVE-2020-12689HIGH8.8An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (...
CVE-2020-12678Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-12677. Reason: This candidate is a reservation d...
CVE-2020-12669HIGH8.8core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restricti...
CVE-2020-11727MEDIUM6.1A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordP...
CVE-2020-8899CRITICAL9.8There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q...
CVE-2020-3334HIGH7.4A vulnerability in the ARP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thr...
CVE-2020-3329MEDIUM4.3A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Direc...
CVE-2020-3318CRITICAL9.8Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software cou...
CVE-2020-3315MEDIUM5.3Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticate...
CVE-2020-3313MEDIUM6.1A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote...
CVE-2020-3312HIGH7.5A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now