2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15591CRITICAL9.8fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote c...
CVE-2020-25721HIGH8.8Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Li...
CVE-2020-36519MEDIUM4.9Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This o...
CVE-2020-4989MEDIUM4.3IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an...
CVE-2020-36518HIGH7.5jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested o...
CVE-2020-36517HIGH7.5An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS oper...
CVE-2020-36123Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-14115CRITICAL9.8A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio...
CVE-2020-14112MEDIUM5.3Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing conf...
CVE-2020-14111HIGH7.8A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio...
CVE-2020-18327MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter i...
CVE-2020-18326HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator f...
CVE-2020-18325MEDIUM6.1Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
CVE-2020-18324MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
CVE-2020-15936MEDIUM4.5A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and b...
CVE-2020-4925MEDIUM5.5A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requ...
CVE-2020-12775CRITICAL9.8Hicos citizen certificate client-side component does not filter special characters for command parameters in specific we...
CVE-2020-22845HIGH7.5A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via craf...
CVE-2020-22844HIGH7.5A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via craf...
CVE-2020-36510MEDIUM6.1The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the r...
CVE-2020-27958MEDIUM4.3The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote auth...
CVE-2020-36516MEDIUM5.9An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID a...
CVE-2020-14504MEDIUM5.3The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, una...
CVE-2020-14502MEDIUM6.1The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker...
CVE-2020-14481HIGH7.8The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticat...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now