2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-9353HIGH7.5An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functional...
CVE-2020-9352CRITICAL9.8An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL fea...
CVE-2020-9351MEDIUM5.3An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerCons...
CVE-2020-9350MEDIUM5.4Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.
CVE-2020-9342MEDIUM5.5The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a ...
CVE-2020-9341HIGH8.8CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&...
CVE-2020-9340HIGH7.2fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter.
CVE-2020-9339MEDIUM5.4SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
CVE-2020-9338MEDIUM5.4SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
CVE-2020-9336MEDIUM5.4fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field...
CVE-2020-9039CRITICAL9.8Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Per...
CVE-2020-8813HIGH8.8graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a...
CVE-2020-8862HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-26...
CVE-2020-8861HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-13...
CVE-2020-8860HIGH8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Fir...
CVE-2020-9330HIGH8.8Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind cred...
CVE-2020-9329MEDIUM5.9Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go ...
CVE-2020-9327HIGH7.5In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault ...
CVE-2020-7907HIGH7.5In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
CVE-2020-6842HIGH7.2D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell...
CVE-2020-6841CRITICAL9.8D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharac...
CVE-2020-5326MEDIUM5.3Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot In...
CVE-2020-5324MEDIUM4.4Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is li...
CVE-2020-5534HIGH8Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arb...
CVE-2020-5533MEDIUM6.1Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arb...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now