2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14480 | MEDIUM | 5.5 | 0.3% | Feb 24, 2022 | Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker coul... |
| CVE-2020-14478 | HIGH | 7.1 | 0.3% | Feb 24, 2022 | A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to ... |
| CVE-2020-10640 | CRITICAL | 9.8 | 3.0% | Feb 24, 2022 | Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges ... |
| CVE-2020-10636 | HIGH | 7.5 | 0.3% | Feb 24, 2022 | Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obta... |
| CVE-2020-10635 | MEDIUM | 4.3 | 0.3% | Feb 24, 2022 | Simulation models for KUKA.Sim Pro version 3.1 are hosted by a server maintained by KUKA. When these devices request a m... |
| CVE-2020-10632 | MEDIUM | 5.3 | 0.5% | Feb 24, 2022 | Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of import... |
| CVE-2020-27467 | HIGH | 7.5 | 15.7% | Feb 24, 2022 | A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. |
| CVE-2020-8242 | HIGH | 7.2 | 0.9% | Feb 18, 2022 | Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user ne... |
| CVE-2020-25722 | HIGH | 8.8 | 1.6% | Feb 18, 2022 | Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker... |
| CVE-2020-25719 | HIGH | 7.2 | 1.7% | Feb 18, 2022 | A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authenticat... |
| CVE-2020-25718 | HIGH | 8.8 | 1.6% | Feb 18, 2022 | A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domai... |
| CVE-2020-25717 | HIGH | 8.1 | 1.6% | Feb 18, 2022 | A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cau... |
| CVE-2020-8107 | HIGH | 7.8 | 0.3% | Feb 18, 2022 | A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper... |
| CVE-2020-6922 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6921 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6920 | MEDIUM | 5.5 | 0.8% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6919 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6918 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-6917 | HIGH | 7.8 | 0.9% | Feb 16, 2022 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h... |
| CVE-2020-26728 | CRITICAL | 9.8 | 3.5% | Feb 11, 2022 | A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allow... |
| CVE-2020-14523 | CRITICAL | 9.8 | 2.2% | Feb 11, 2022 | Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitra... |
| CVE-2020-14521 | CRITICAL | 9.8 | 1.2% | Feb 11, 2022 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerabil... |
| CVE-2020-36062 | CRITICAL | 9.8 | 2.3% | Feb 11, 2022 | Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows a... |
| CVE-2020-13677 | HIGH | 7.5 | 1.0% | Feb 11, 2022 | Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which ma... |
| CVE-2020-13676 | MEDIUM | 6.5 | 0.8% | Feb 11, 2022 | The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now