2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9209 | MEDIUM | 6.7 | 0.2% | Jan 13, 2021 | There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located impro... |
| CVE-2020-1866 | MEDIUM | 6.5 | 0.4% | Jan 13, 2021 | There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended b... |
| CVE-2020-1865 | MEDIUM | 6.5 | 0.3% | Jan 13, 2021 | There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the... |
| CVE-2020-9143 | MEDIUM | 5.3 | 0.7% | Jan 13, 2021 | There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability ... |
| CVE-2020-9138 | MEDIUM | 5.3 | 0.7% | Jan 13, 2021 | There is a heap-based buffer overflow vulnerability in some Huawei Smartphone, Successful exploit of this vulnerability ... |
| CVE-2020-4604 | MEDIUM | 4.4 | 0.2% | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local privile... |
| CVE-2020-4602 | MEDIUM | 4.4 | 0.3% | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. I... |
| CVE-2020-4600 | MEDIUM | 5.3 | 1.3% | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed techn... |
| CVE-2020-4599 | MEDIUM | 5.3 | 1.3% | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed techn... |
| CVE-2020-4597 | MEDIUM | 4.3 | 0.6% | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies. Attac... |
| CVE-2020-35687 | MEDIUM | 4.3 | 1.4% | Jan 13, 2021 | PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker ... |
| CVE-2020-15221 | MEDIUM | 5.4 | 0.6% | Jan 13, 2021 | Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target bro... |
| CVE-2020-15220 | MEDIUM | 6.1 | 0.7% | Jan 13, 2021 | Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created... |
| CVE-2020-15219 | MEDIUM | 4.3 | 0.7% | Jan 13, 2021 | Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error i... |
| CVE-2020-15218 | MEDIUM | 6.8 | 0.8% | Jan 13, 2021 | Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached,... |
| CVE-2020-36191 | MEDIUM | 4.5 | 0.5% | Jan 13, 2021 | JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/u... |
| CVE-2020-28395 | MEDIUM | 5.9 | 1.2% | Jan 12, 2021 | A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch fa... |
| CVE-2020-28391 | MEDIUM | 5.9 | 1.1% | Jan 12, 2021 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),... |
| CVE-2020-28390 | MEDIUM | 5.5 | 0.4% | Jan 12, 2021 | A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application c... |
| CVE-2020-26981 | MEDIUM | 6.5 | 2.6% | Jan 12, 2021 | A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0)... |
| CVE-2020-15799 | MEDIUM | 6.5 | 1.1% | Jan 12, 2021 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),... |
| CVE-2020-36190 | MEDIUM | 6.1 | 1.3% | Jan 12, 2021 | RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms. |
| CVE-2020-13116 | MEDIUM | 5.4 | 0.5% | Jan 12, 2021 | OpenText Carbonite Server Backup Portal before 8.8.7 allows XSS by an authenticated user via policy creation. |
| CVE-2020-4838 | MEDIUM | 5.4 | 0.6% | Jan 12, 2021 | IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to stored cross-site scripting. This vulnerability allows users t... |
| CVE-2020-4674 | MEDIUM | 4.3 | 0.8% | Jan 12, 2021 | IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system. IBM X-F... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now