2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-1773HIGH8.1An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or b...
CVE-2020-1772HIGH7.5It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid...
CVE-2020-1771MEDIUM5.4Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When age...
CVE-2020-1770MEDIUM4.3Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue af...
CVE-2020-1769MEDIUM4.3In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be co...
CVE-2020-10510MEDIUM6.5Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. Afte...
CVE-2020-10509MEDIUM6.1Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), a...
CVE-2020-10508HIGH7.5Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a spe...
CVE-2020-3936CRITICAL9.8UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, ...
CVE-2020-3921HIGH7.5UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts informa...
CVE-2020-3920HIGH8.1UltraLog Express device management interface does not properly perform access authentication in some specific pages/func...
CVE-2020-10993CRITICAL9.1Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java.
CVE-2020-10992CRITICAL9.8Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.
CVE-2020-10991CRITICAL9.8Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
CVE-2020-10990CRITICAL9.8An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.j...
CVE-2020-9468MEDIUM4.3The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do n...
CVE-2020-9467MEDIUM5.4Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
CVE-2020-10828CRITICAL9.8A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote ...
CVE-2020-10827CRITICAL9.8A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote ...
CVE-2020-10826CRITICAL9.8/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to ach...
CVE-2020-10825CRITICAL9.8A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigo...
CVE-2020-10824CRITICAL9.8A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vig...
CVE-2020-10823CRITICAL9.8A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor3...
CVE-2020-9521HIGH8.8An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.0...
CVE-2020-9066HIGH7.8Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vuln...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now