2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11664 | MEDIUM | 6.1 | 1.4% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attack... |
| CVE-2020-11663 | MEDIUM | 6.1 | 1.3% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform ... |
| CVE-2020-11662 | HIGH | 7.5 | 3.2% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-... |
| CVE-2020-11661 | HIGH | 8.1 | 1.9% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit ... |
| CVE-2020-10951 | MEDIUM | 4.7 | 0.9% | Apr 15, 2020 | Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages. |
| CVE-2020-6996 | CRITICAL | 9.8 | 1.3% | Apr 15, 2020 | Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source ... |
| CVE-2020-11799 | CRITICAL | 9.8 | 1.2% | Apr 15, 2020 | Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This ca... |
| CVE-2020-10615 | HIGH | 7.5 | 2.6% | Apr 15, 2020 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers caus... |
| CVE-2020-10613 | HIGH | 7.5 | 2.5% | Apr 15, 2020 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to d... |
| CVE-2020-10611 | CRITICAL | 9.8 | 5.2% | Apr 15, 2020 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to e... |
| CVE-2020-5350 | HIGH | 7.2 | 2.0% | Apr 15, 2020 | Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability... |
| CVE-2020-5346 | MEDIUM | 4.8 | 0.6% | Apr 15, 2020 | RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security... |
| CVE-2020-3954 | MEDIUM | 6.1 | 0.8% | Apr 15, 2020 | Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. |
| CVE-2020-3953 | MEDIUM | 4.8 | 0.7% | Apr 15, 2020 | Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input vali... |
| CVE-2020-11792 | HIGH | 7.5 | 0.7% | Apr 15, 2020 | NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certifi... |
| CVE-2020-11791 | MEDIUM | 6.1 | 0.6% | Apr 15, 2020 | NETGEAR JGS516PE devices before 2.6.0.43 are affected by reflected XSS. |
| CVE-2020-11790 | CRITICAL | 9.8 | 2.4% | Apr 15, 2020 | NETGEAR R7800 devices before 1.0.2.68 are affected by remote code execution by unauthenticated attackers. |
| CVE-2020-11789 | CRITICAL | 9.8 | 2.7% | Apr 15, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.... |
| CVE-2020-11788 | HIGH | 8.8 | 0.6% | Apr 15, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.6... |
| CVE-2020-11787 | MEDIUM | 4.8 | 0.4% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-6992 | MEDIUM | 6.7 | 0.4% | Apr 15, 2020 | A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and ... |
| CVE-2020-11786 | MEDIUM | 4.8 | 0.5% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-11785 | MEDIUM | 4.8 | 0.4% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-11784 | MEDIUM | 4.8 | 0.4% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-10639 | HIGH | 7.8 | 0.8% | Apr 15, 2020 | Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now