2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0467 | MEDIUM | 5.5 | 0.2% | Dec 14, 2020 | In onUserStopped of Vpn.java, there is a possible resetting of user preferences due to a logic issue. This could lead to... |
| CVE-2020-0465 | MEDIUM | 6.8 | 0.3% | Dec 14, 2020 | In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This coul... |
| CVE-2020-0464 | MEDIUM | 5.5 | 0.2% | Dec 14, 2020 | In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to loc... |
| CVE-2020-25233 | MEDIUM | 5.5 | 0.2% | Dec 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The firmware update of ... |
| CVE-2020-25231 | MEDIUM | 5.5 | 0.2% | Dec 14, 2020 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All... |
| CVE-2020-29511 | MEDIUM | 5.6 | 1.9% | Dec 14, 2020 | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes du... |
| CVE-2020-29510 | MEDIUM | 5.6 | 2.0% | Dec 14, 2020 | The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during ... |
| CVE-2020-29509 | MEDIUM | 5.6 | 2.1% | Dec 14, 2020 | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes ... |
| CVE-2020-29304 | MEDIUM | 6.1 | 5.5% | Dec 14, 2020 | A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and p... |
| CVE-2020-29303 | MEDIUM | 6.1 | 1.9% | Dec 14, 2020 | A cross-site scripting (XSS) vulnerability in the SabaiApp Directories Pro plugin 1.3.45 for WordPress allows remote att... |
| CVE-2020-28861 | MEDIUM | 5.3 | 2.3% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV ... |
| CVE-2020-28859 | MEDIUM | 6.1 | 0.8% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple par... |
| CVE-2020-28857 | MEDIUM | 6.1 | 1.5% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple pa... |
| CVE-2020-15733 | MEDIUM | 6.5 | 0.6% | Dec 14, 2020 | An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to... |
| CVE-2020-17513 | MEDIUM | 5.3 | 4.3% | Dec 14, 2020 | In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable... |
| CVE-2020-17511 | MEDIUM | 6.5 | 2.5% | Dec 14, 2020 | In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in ... |
| CVE-2020-35236 | MEDIUM | 5.3 | 1.2% | Dec 14, 2020 | The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deleti... |
| CVE-2020-5637 | MEDIUM | 6.8 | 0.4% | Dec 14, 2020 | Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows... |
| CVE-2020-5636 | MEDIUM | 6.8 | 0.7% | Dec 14, 2020 | Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specia... |
| CVE-2020-35208 | MEDIUM | 5.7 | 0.5% | Dec 12, 2020 | An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. T... |
| CVE-2020-35207 | MEDIUM | 5.7 | 0.5% | Dec 12, 2020 | An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. T... |
| CVE-2020-35202 | MEDIUM | 5.4 | 0.7% | Dec 12, 2020 | Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS. |
| CVE-2020-35201 | MEDIUM | 5.4 | 0.7% | Dec 12, 2020 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS. |
| CVE-2020-35200 | MEDIUM | 6.1 | 0.9% | Dec 12, 2020 | Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS. |
| CVE-2020-35199 | MEDIUM | 5.4 | 0.6% | Dec 12, 2020 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now