2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-28976MEDIUM5.3The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make...
CVE-2020-27659MEDIUM4.8Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to i...
CVE-2020-25624MEDIUM5hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
CVE-2020-29380MEDIUM5.9An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a...
CVE-2020-29379MEDIUM5.5An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating ...
CVE-2020-29373MEDIUM6.5An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during p...
CVE-2020-29372MEDIUM4.7An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition betwee...
CVE-2020-27218MEDIUM4.8In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2...
CVE-2020-29138MEDIUM5.3Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, all...
CVE-2020-25738MEDIUM5.5CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism ...
CVE-2020-29145MEDIUM5.4In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS v...
CVE-2020-29144MEDIUM5.4In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via...
CVE-2020-29137MEDIUM6.1cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
CVE-2020-29136MEDIUM6.5In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
CVE-2020-29135MEDIUM4.1cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
CVE-2020-29133MEDIUM6.1jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename...
CVE-2020-12262MEDIUM5.4Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= ...
CVE-2020-29130MEDIUM4.3slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even i...
CVE-2020-29129MEDIUM4.3ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if...
CVE-2020-27663MEDIUM4.3In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows...
CVE-2020-27662MEDIUM4.3In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an atta...
CVE-2020-13886MEDIUM5.3Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?pag...
CVE-2020-25653MEDIUM6.3A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw ...
CVE-2020-25652MEDIUM5.5A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be establish...
CVE-2020-25651MEDIUM6.4A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now