2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35176MEDIUM5.3In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even...
CVE-2020-35175MEDIUM5.3Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.
CVE-2020-17470MEDIUM5.3An issue was discovered in FNET through 4.6.4. The code that initializes the DNS client interface structure does not set...
CVE-2020-15376MEDIUM4.3Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness ...
CVE-2020-15375MEDIUM6.7Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input vali...
CVE-2020-29455MEDIUM6.1A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressP...
CVE-2020-5950MEDIUM5.3On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to ...
CVE-2020-35149MEDIUM5.3lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied...
CVE-2020-27825MEDIUM5.7A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race proble...
CVE-2020-26421MEDIUM5.3Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of...
CVE-2020-26420MEDIUM5.3Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injecti...
CVE-2020-26419MEDIUM5.3Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture...
CVE-2020-26418MEDIUM5.3Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet inject...
CVE-2020-26265MEDIUM5.3Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and b...
CVE-2020-26264MEDIUM6.5Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a ...
CVE-2020-15023MEDIUM5.9Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arise...
CVE-2020-12149MEDIUM6.8The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly in...
CVE-2020-12148MEDIUM6.8A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allo...
CVE-2020-17515MEDIUM6.1The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects...
CVE-2020-7790MEDIUM5.3This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able ...
CVE-2020-7789MEDIUM5.6This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines d...
CVE-2020-35132MEDIUM5.4An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be ...
CVE-2020-35127MEDIUM5.4Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.
CVE-2020-26411MEDIUM4.3A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 t...
CVE-2020-35126MEDIUM4.8Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now