2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7252MEDIUM5.5Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows lo...
CVE-2020-5531CRITICAL9.8Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V,...
CVE-2020-9033MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9032MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9031MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9030MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9029MEDIUM6.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traver...
CVE-2020-9028MEDIUM6.1Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via t...
CVE-2020-9027CRITICAL9.8ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The N...
CVE-2020-9026CRITICAL9.8ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NT...
CVE-2020-9025MEDIUM6.1Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Vie...
CVE-2020-9024CRITICAL9.8Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (e...
CVE-2020-9023CRITICAL9.8Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured wit...
CVE-2020-9022MEDIUM6.1An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter all...
CVE-2020-9021CRITICAL9.8Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12....
CVE-2020-9020CRITICAL9.8Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timecon...
CVE-2020-9034HIGH7.5Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session vali...
CVE-2020-9016MEDIUM5.4Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
CVE-2020-9013MEDIUM4.3Arvato Skillpipe 3.0 allows attackers to bypass intended print restrictions by deleting <div id="watermark"> from the HT...
CVE-2020-9012MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows ...
CVE-2020-9007MEDIUM5.4Codoforum 4.8.8 allows self-XSS via the title of a new topic.
CVE-2020-8997HIGH8.8Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to ...
CVE-2020-8996MEDIUM4.3AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwi...
CVE-2020-7050MEDIUM5.4Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to...
CVE-2020-8129CRITICAL9.8An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execu...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now