2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29070 | MEDIUM | 4.8 | 1.1% | Nov 25, 2020 | osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of n... |
| CVE-2020-26212 | MEDIUM | 6.5 | 1.2% | Nov 25, 2020 | GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that ... |
| CVE-2020-25650 | MEDIUM | 5.5 | 0.5% | Nov 25, 2020 | A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine... |
| CVE-2020-29072 | MEDIUM | 6.1 | 0.7% | Nov 25, 2020 | A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires use... |
| CVE-2020-29069 | MEDIUM | 5.5 | 0.3% | Nov 25, 2020 | _get_flag_ip_localdb in server/mhn/ui/utils.py in Modern Honey Network (MHN) through 2020-11-23 allows attackers to caus... |
| CVE-2020-26235 | MEDIUM | 5.3 | 1.9% | Nov 24, 2020 | In Rust time crate from version 0.2.7 and before version 0.2.23, unix-like operating systems may segfault due to derefer... |
| CVE-2020-29055 | MEDIUM | 5.9 | 0.7% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-26232 | MEDIUM | 5.4 | 0.8% | Nov 24, 2020 | Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server c... |
| CVE-2020-29053 | MEDIUM | 6.1 | 0.7% | Nov 24, 2020 | HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter. |
| CVE-2020-28330 | MEDIUM | 6.5 | 1.1% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker ... |
| CVE-2020-25640 | MEDIUM | 5.3 | 1.3% | Nov 24, 2020 | A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning lev... |
| CVE-2020-28928 | MEDIUM | 5.5 | 0.6% | Nov 24, 2020 | In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source characte... |
| CVE-2020-28726 | MEDIUM | 6.1 | 0.6% | Nov 24, 2020 | Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php. |
| CVE-2020-24815 | MEDIUM | 6.5 | 2.1% | Nov 24, 2020 | A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 ... |
| CVE-2020-10763 | MEDIUM | 5.5 | 0.4% | Nov 24, 2020 | An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an... |
| CVE-2020-10762 | MEDIUM | 5.5 | 0.3% | Nov 24, 2020 | An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block C... |
| CVE-2020-4003 | MEDIUM | 6.5 | 1.1% | Nov 24, 2020 | VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulne... |
| CVE-2020-3984 | MEDIUM | 6.5 | 22.4% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which a... |
| CVE-2020-25474 | MEDIUM | 6.1 | 0.9% | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name p... |
| CVE-2020-25473 | MEDIUM | 6.5 | 0.9% | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies. |
| CVE-2020-25472 | MEDIUM | 6.5 | 0.5% | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows ... |
| CVE-2020-5641 | MEDIUM | 6.5 | 0.6% | Nov 24, 2020 | Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers... |
| CVE-2020-29003 | MEDIUM | 5.4 | 0.5% | Nov 24, 2020 | The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Spec... |
| CVE-2020-29002 | MEDIUM | 4.8 | 0.5% | Nov 24, 2020 | includes/CologneBlueTemplate.php in the CologneBlue skin for MediaWiki through 1.35 allows XSS via a qbfind message supp... |
| CVE-2020-28348 | MEDIUM | 6.5 | 1.6% | Nov 24, 2020 | HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not exp... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now