2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11664MEDIUM6.1CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attack...
CVE-2020-11663MEDIUM6.1CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform ...
CVE-2020-11662HIGH7.5CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-...
CVE-2020-11661HIGH8.1CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit ...
CVE-2020-10951MEDIUM4.7Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
CVE-2020-6996CRITICAL9.8Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source ...
CVE-2020-11799CRITICAL9.8Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This ca...
CVE-2020-10615HIGH7.5Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers caus...
CVE-2020-10613HIGH7.5Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to d...
CVE-2020-10611CRITICAL9.8Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to e...
CVE-2020-5350HIGH7.2Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability...
CVE-2020-5346MEDIUM4.8RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security...
CVE-2020-3954MEDIUM6.1Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
CVE-2020-3953MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input vali...
CVE-2020-11792HIGH7.5NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certifi...
CVE-2020-11791MEDIUM6.1NETGEAR JGS516PE devices before 2.6.0.43 are affected by reflected XSS.
CVE-2020-11790CRITICAL9.8NETGEAR R7800 devices before 1.0.2.68 are affected by remote code execution by unauthenticated attackers.
CVE-2020-11789CRITICAL9.8Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1....
CVE-2020-11788HIGH8.8Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.6...
CVE-2020-11787MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-6992MEDIUM6.7A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and ...
CVE-2020-11786MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-11785MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-11784MEDIUM4.8Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b...
CVE-2020-10639HIGH7.8Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now