2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14480MEDIUM5.5Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker coul...
CVE-2020-14478HIGH7.1A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to ...
CVE-2020-10640CRITICAL9.8Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges ...
CVE-2020-10636HIGH7.5Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obta...
CVE-2020-10635MEDIUM4.3Simulation models for KUKA.Sim Pro version 3.1 are hosted by a server maintained by KUKA. When these devices request a m...
CVE-2020-10632MEDIUM5.3Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of import...
CVE-2020-27467HIGH7.5A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.
CVE-2020-8242HIGH7.2Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user ne...
CVE-2020-25722HIGH8.8Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker...
CVE-2020-25719HIGH7.2A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authenticat...
CVE-2020-25718HIGH8.8A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domai...
CVE-2020-25717HIGH8.1A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cau...
CVE-2020-8107HIGH7.8A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper...
CVE-2020-6922HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6921HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6920MEDIUM5.5Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6919HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6918HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-6917HIGH7.8Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients h...
CVE-2020-26728CRITICAL9.8A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allow...
CVE-2020-14523CRITICAL9.8Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitra...
CVE-2020-14521CRITICAL9.8Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerabil...
CVE-2020-36062CRITICAL9.8Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows a...
CVE-2020-13677HIGH7.5Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which ma...
CVE-2020-13676MEDIUM6.5The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now