2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35176 | MEDIUM | 5.3 | 1.8% | Dec 12, 2020 | In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even... |
| CVE-2020-35175 | MEDIUM | 5.3 | 0.9% | Dec 11, 2020 | Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API. |
| CVE-2020-17470 | MEDIUM | 5.3 | 2.1% | Dec 11, 2020 | An issue was discovered in FNET through 4.6.4. The code that initializes the DNS client interface structure does not set... |
| CVE-2020-15376 | MEDIUM | 4.3 | 0.9% | Dec 11, 2020 | Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness ... |
| CVE-2020-15375 | MEDIUM | 6.7 | 0.3% | Dec 11, 2020 | Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input vali... |
| CVE-2020-29455 | MEDIUM | 6.1 | 1.1% | Dec 11, 2020 | A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressP... |
| CVE-2020-5950 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to ... |
| CVE-2020-35149 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied... |
| CVE-2020-27825 | MEDIUM | 5.7 | 0.3% | Dec 11, 2020 | A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race proble... |
| CVE-2020-26421 | MEDIUM | 5.3 | 2.6% | Dec 11, 2020 | Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of... |
| CVE-2020-26420 | MEDIUM | 5.3 | 2.6% | Dec 11, 2020 | Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injecti... |
| CVE-2020-26419 | MEDIUM | 5.3 | 2.8% | Dec 11, 2020 | Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture... |
| CVE-2020-26418 | MEDIUM | 5.3 | 3.0% | Dec 11, 2020 | Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet inject... |
| CVE-2020-26265 | MEDIUM | 5.3 | 0.9% | Dec 11, 2020 | Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and b... |
| CVE-2020-26264 | MEDIUM | 6.5 | 1.9% | Dec 11, 2020 | Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a ... |
| CVE-2020-15023 | MEDIUM | 5.9 | 1.6% | Dec 11, 2020 | Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arise... |
| CVE-2020-12149 | MEDIUM | 6.8 | 1.3% | Dec 11, 2020 | The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly in... |
| CVE-2020-12148 | MEDIUM | 6.8 | 2.1% | Dec 11, 2020 | A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allo... |
| CVE-2020-17515 | MEDIUM | 6.1 | 16.0% | Dec 11, 2020 | The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects... |
| CVE-2020-7790 | MEDIUM | 5.3 | 1.0% | Dec 11, 2020 | This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able ... |
| CVE-2020-7789 | MEDIUM | 5.6 | 1.6% | Dec 11, 2020 | This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines d... |
| CVE-2020-35132 | MEDIUM | 5.4 | 1.3% | Dec 11, 2020 | An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be ... |
| CVE-2020-35127 | MEDIUM | 5.4 | 0.6% | Dec 11, 2020 | Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS. |
| CVE-2020-26411 | MEDIUM | 4.3 | 1.2% | Dec 11, 2020 | A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 t... |
| CVE-2020-35126 | MEDIUM | 4.8 | 0.7% | Dec 11, 2020 | Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now