2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28246 | CRITICAL | 9.8 | 2.2% | Jun 2, 2022 | A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during dele... |
| CVE-2020-20971 | HIGH | 8.8 | 0.5% | Jun 2, 2022 | Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index. |
| CVE-2020-26185 | HIGH | 7.5 | 1.0% | Jun 1, 2022 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. |
| CVE-2020-26184 | HIGH | 7.5 | 0.6% | Jun 1, 2022 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability. |
| CVE-2020-4926 | CRITICAL | 9.1 | 0.6% | May 24, 2022 | A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized acc... |
| CVE-2020-4107 | HIGH | 7.8 | 0.2% | May 19, 2022 | HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to t... |
| CVE-2020-16235 | MEDIUM | 6.5 | 0.1% | May 19, 2022 | Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access fiel... |
| CVE-2020-16231 | HIGH | 8.8 | 0.8% | May 19, 2022 | The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect ... |
| CVE-2020-16209 | CRITICAL | 9.8 | 1.4% | May 19, 2022 | A malicious attacker could exploit the interface of the Fieldcomm Group HART-IP (release 1.0.0.0) by constructing messag... |
| CVE-2020-14496 | CRITICAL | 9.8 | 0.8% | May 19, 2022 | Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software P... |
| CVE-2020-4970 | MEDIUM | 5.9 | 0.7% | May 19, 2022 | IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensit... |
| CVE-2020-4994 | HIGH | 7.5 | 1.4% | May 17, 2022 | IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a ... |
| CVE-2020-4957 | MEDIUM | 5.3 | 0.8% | May 17, 2022 | IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that coul... |
| CVE-2020-22983 | HIGH | 8.1 | 2.5% | May 13, 2022 | A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unaut... |
| CVE-2020-22987 | MEDIUM | 6.1 | 1.4% | May 12, 2022 | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attac... |
| CVE-2020-22986 | MEDIUM | 6.1 | 1.5% | May 12, 2022 | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attac... |
| CVE-2020-22985 | MEDIUM | 6.1 | 1.5% | May 12, 2022 | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attac... |
| CVE-2020-22984 | MEDIUM | 6.1 | 1.5% | May 12, 2022 | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attac... |
| CVE-2020-19228 | HIGH | 7.2 | 1.3% | May 11, 2022 | An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary fi... |
| CVE-2020-19217 | HIGH | 8.8 | 0.9% | May 6, 2022 | SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?... |
| CVE-2020-19216 | HIGH | 8.8 | 0.9% | May 6, 2022 | SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group... |
| CVE-2020-19215 | HIGH | 8.8 | 0.9% | May 6, 2022 | SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_... |
| CVE-2020-19213 | CRITICAL | 9.8 | 15.8% | May 6, 2022 | SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. |
| CVE-2020-19212 | MEDIUM | 4.9 | 0.8% | May 6, 2022 | SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete. |
| CVE-2020-23621 | CRITICAL | 9.8 | 1.9% | May 2, 2022 | The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerabili... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now