2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28976 | MEDIUM | 5.3 | 26.0% | Nov 30, 2020 | The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make... |
| CVE-2020-27659 | MEDIUM | 4.8 | 5.1% | Nov 30, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to i... |
| CVE-2020-25624 | MEDIUM | 5 | 0.6% | Nov 30, 2020 | hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver. |
| CVE-2020-29380 | MEDIUM | 5.9 | 0.5% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a... |
| CVE-2020-29379 | MEDIUM | 5.5 | 0.3% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating ... |
| CVE-2020-29373 | MEDIUM | 6.5 | 0.5% | Nov 28, 2020 | An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during p... |
| CVE-2020-29372 | MEDIUM | 4.7 | 0.4% | Nov 28, 2020 | An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition betwee... |
| CVE-2020-27218 | MEDIUM | 4.8 | 8.1% | Nov 28, 2020 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2... |
| CVE-2020-29138 | MEDIUM | 5.3 | 1.1% | Nov 27, 2020 | Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, all... |
| CVE-2020-25738 | MEDIUM | 5.5 | 0.4% | Nov 27, 2020 | CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism ... |
| CVE-2020-29145 | MEDIUM | 5.4 | 0.5% | Nov 27, 2020 | In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS v... |
| CVE-2020-29144 | MEDIUM | 5.4 | 0.5% | Nov 27, 2020 | In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via... |
| CVE-2020-29137 | MEDIUM | 6.1 | 0.6% | Nov 27, 2020 | cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577). |
| CVE-2020-29136 | MEDIUM | 6.5 | 1.2% | Nov 27, 2020 | In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575). |
| CVE-2020-29135 | MEDIUM | 4.1 | 0.6% | Nov 27, 2020 | cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567). |
| CVE-2020-29133 | MEDIUM | 6.1 | 1.1% | Nov 27, 2020 | jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename... |
| CVE-2020-12262 | MEDIUM | 5.4 | 1.5% | Nov 27, 2020 | Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= ... |
| CVE-2020-29130 | MEDIUM | 4.3 | 1.8% | Nov 26, 2020 | slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even i... |
| CVE-2020-29129 | MEDIUM | 4.3 | 1.4% | Nov 26, 2020 | ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if... |
| CVE-2020-27663 | MEDIUM | 4.3 | 0.9% | Nov 26, 2020 | In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows... |
| CVE-2020-27662 | MEDIUM | 4.3 | 0.7% | Nov 26, 2020 | In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an atta... |
| CVE-2020-13886 | MEDIUM | 5.3 | 4.3% | Nov 26, 2020 | Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?pag... |
| CVE-2020-25653 | MEDIUM | 6.3 | 0.3% | Nov 26, 2020 | A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw ... |
| CVE-2020-25652 | MEDIUM | 5.5 | 0.4% | Nov 26, 2020 | A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be establish... |
| CVE-2020-25651 | MEDIUM | 6.4 | 0.3% | Nov 26, 2020 | A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now