2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3933MEDIUM5.3TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, allows attackers to enumerate ...
CVE-2020-8841HIGH8.8An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint i...
CVE-2020-8840CRITICAL9.8FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apac...
CVE-2020-8089MEDIUM5.4Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
CVE-2020-1697MEDIUM5.4It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin ...
CVE-2020-8825MEDIUM5.4index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
CVE-2020-7060CRITICAL9.1When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7....
CVE-2020-7059CRITICAL9.1When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 an...
CVE-2020-8823MEDIUM6.1htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka cal...
CVE-2020-8822MEDIUM4.8Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.
CVE-2020-8812MEDIUM5.4Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's per...
CVE-2020-8811MEDIUM4.3ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.
CVE-2020-8808HIGH7.8The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged us...
CVE-2020-6770CRITICAL9.8Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker ...
CVE-2020-6768HIGH7.5A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated ...
CVE-2020-1708HIGH7It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3,...
CVE-2020-1700MEDIUM6.5A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can a...
CVE-2020-8796CRITICAL9.8Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the serve...
CVE-2020-6769CRITICAL9.1Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote...
CVE-2020-1768MEDIUM5.4The external frontend system uses numerous background calls to the backend. Each background request is treated as user a...
CVE-2020-8126HIGH7.8A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resul...
CVE-2020-8788MEDIUM6.1Synaptive Medical ClearCanvas ImageServer 3.0 Alpha allows XSS (and HTML injection) via the Default.aspx UserName parame...
CVE-2020-8656CRITICAL9.8An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe...
CVE-2020-8655HIGH7.8An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability...
CVE-2020-8654HIGH8.8An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now