2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28246CRITICAL9.8A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during dele...
CVE-2020-20971HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.
CVE-2020-26185HIGH7.5Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
CVE-2020-26184HIGH7.5Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
CVE-2020-4926CRITICAL9.1A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized acc...
CVE-2020-4107HIGH7.8HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to t...
CVE-2020-16235MEDIUM6.5Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access fiel...
CVE-2020-16231HIGH8.8The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect ...
CVE-2020-16209CRITICAL9.8A malicious attacker could exploit the interface of the Fieldcomm Group HART-IP (release 1.0.0.0) by constructing messag...
CVE-2020-14496CRITICAL9.8Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software P...
CVE-2020-4970MEDIUM5.9IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensit...
CVE-2020-4994HIGH7.5IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a ...
CVE-2020-4957MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that coul...
CVE-2020-22983HIGH8.1A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unaut...
CVE-2020-22987MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attac...
CVE-2020-22986MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attac...
CVE-2020-22985MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attac...
CVE-2020-22984MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attac...
CVE-2020-19228HIGH7.2An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary fi...
CVE-2020-19217HIGH8.8SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?...
CVE-2020-19216HIGH8.8SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group...
CVE-2020-19215HIGH8.8SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_...
CVE-2020-19213CRITICAL9.8SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
CVE-2020-19212MEDIUM4.9SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
CVE-2020-23621CRITICAL9.8The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerabili...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now