2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-1816HIGH7.5Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001...
CVE-2020-1815HIGH7.5Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001...
CVE-2020-1811HIGH8.8GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote a...
CVE-2020-8768CRITICAL9.4An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. ...
CVE-2020-7959MEDIUM5.3LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application e...
CVE-2020-1856HIGH7.5Huawei NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, and USG9500 versions V500R001C30, V500R001C6...
CVE-2020-1853MEDIUM6.5GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an aut...
CVE-2020-1841HIGH7.5Huawei CloudLink Board version 20.0.0; DP300 version V500R002C00; RSE6500 versions V100R001C00, V500R002C00, and V500R00...
CVE-2020-1829HIGH7.5Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200,...
CVE-2020-1827HIGH7.5Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 version...
CVE-2020-1858HIGH7.5Huawei products NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; Secospace USG6600 versions V500R...
CVE-2020-1857MEDIUM5.5Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 version...
CVE-2020-1828HIGH7.5Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500...
CVE-2020-1693CRITICAL9.8A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api ...
CVE-2020-7597HIGH8.8codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of...
CVE-2020-9043HIGH8.8The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.
CVE-2020-1704HIGH7.8An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maist...
CVE-2020-9038MEDIUM5.4Joplin through 1.0.184 allows Arbitrary File Read via XSS.
CVE-2020-6850MEDIUM6.1Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML ...
CVE-2020-1692MEDIUM6.5Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same cours...
CVE-2020-9006CRITICAL9.8The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups funct...
CVE-2020-8795HIGH7.5In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unau...
CVE-2020-8518CRITICAL9.8Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu...
CVE-2020-8427CRITICAL9.8In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that...
CVE-2020-9005HIGH7.8meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now