2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15591 | CRITICAL | 9.8 | 3.8% | Mar 17, 2022 | fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote c... |
| CVE-2020-25721 | HIGH | 8.8 | 2.0% | Mar 16, 2022 | Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Li... |
| CVE-2020-36519 | MEDIUM | 4.9 | 0.8% | Mar 16, 2022 | Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This o... |
| CVE-2020-4989 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an... |
| CVE-2020-36518 | HIGH | 7.5 | 4.9% | Mar 11, 2022 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested o... |
| CVE-2020-36517 | HIGH | 7.5 | 2.9% | Mar 10, 2022 | An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS oper... |
| CVE-2020-36123 | — | — | — | Mar 10, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-14115 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio... |
| CVE-2020-14112 | MEDIUM | 5.3 | 0.7% | Mar 10, 2022 | Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing conf... |
| CVE-2020-14111 | HIGH | 7.8 | 0.3% | Mar 10, 2022 | A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio... |
| CVE-2020-18327 | MEDIUM | 6.1 | 0.9% | Mar 4, 2022 | Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter i... |
| CVE-2020-18326 | HIGH | 8.8 | 2.2% | Mar 4, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator f... |
| CVE-2020-18325 | MEDIUM | 6.1 | 2.1% | Mar 4, 2022 | Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel. |
| CVE-2020-18324 | MEDIUM | 6.1 | 2.7% | Mar 4, 2022 | Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template. |
| CVE-2020-15936 | MEDIUM | 4.5 | 0.6% | Mar 1, 2022 | A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and b... |
| CVE-2020-4925 | MEDIUM | 5.5 | 0.2% | Mar 1, 2022 | A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requ... |
| CVE-2020-12775 | CRITICAL | 9.8 | 2.9% | Mar 1, 2022 | Hicos citizen certificate client-side component does not filter special characters for command parameters in specific we... |
| CVE-2020-22845 | HIGH | 7.5 | 1.2% | Feb 28, 2022 | A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via craf... |
| CVE-2020-22844 | HIGH | 7.5 | 1.2% | Feb 28, 2022 | A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via craf... |
| CVE-2020-36510 | MEDIUM | 6.1 | 2.6% | Feb 28, 2022 | The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the r... |
| CVE-2020-27958 | MEDIUM | 4.3 | 1.0% | Feb 26, 2022 | The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote auth... |
| CVE-2020-36516 | MEDIUM | 5.9 | 0.7% | Feb 26, 2022 | An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID a... |
| CVE-2020-14504 | MEDIUM | 5.3 | 1.2% | Feb 24, 2022 | The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, una... |
| CVE-2020-14502 | MEDIUM | 6.1 | 1.0% | Feb 24, 2022 | The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker... |
| CVE-2020-14481 | HIGH | 7.8 | 0.2% | Feb 24, 2022 | The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticat... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now