2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19668 | MEDIUM | 6.5 | 0.9% | Nov 20, 2020 | Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6... |
| CVE-2020-4788 | MEDIUM | 4.7 | 0.4% | Nov 20, 2020 | IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the dat... |
| CVE-2020-7573 | MEDIUM | 6.5 | 1.4% | Nov 19, 2020 | A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that cou... |
| CVE-2020-7571 | MEDIUM | 5.4 | 0.8% | Nov 19, 2020 | A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerabi... |
| CVE-2020-7570 | MEDIUM | 5.4 | 0.8% | Nov 19, 2020 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists ... |
| CVE-2020-7568 | MEDIUM | 4.3 | 0.5% | Nov 19, 2020 | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all referenc... |
| CVE-2020-7567 | MEDIUM | 5.7 | 0.2% | Nov 19, 2020 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that... |
| CVE-2020-28954 | MEDIUM | 5.3 | 1.2% | Nov 19, 2020 | web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrate... |
| CVE-2020-28953 | MEDIUM | 4.3 | 0.7% | Nov 19, 2020 | In BigBlueButton before 2.2.29, a user can vote more than once in a single poll. |
| CVE-2020-28350 | MEDIUM | 6.1 | 0.7% | Nov 19, 2020 | A Cross Site Scripting (XSS) vulnerability exists in OPAC in Sokrates SOWA SowaSQL through 5.6.1 via the sowacgi.php typ... |
| CVE-2020-28210 | MEDIUM | 6.1 | 0.9% | Nov 19, 2020 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoS... |
| CVE-2020-28941 | MEDIUM | 5.5 | 0.3% | Nov 19, 2020 | An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers ... |
| CVE-2020-28947 | MEDIUM | 6.1 | 0.8% | Nov 19, 2020 | In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled. |
| CVE-2020-22394 | MEDIUM | 6.1 | 0.7% | Nov 19, 2020 | In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability. |
| CVE-2020-12496 | MEDIUM | 6.5 | 0.8% | Nov 19, 2020 | Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45... |
| CVE-2020-28942 | MEDIUM | 4.3 | 0.4% | Nov 19, 2020 | An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protoc... |
| CVE-2020-25703 | MEDIUM | 5.3 | 1.5% | Nov 19, 2020 | The participants table download in Moodle always included user emails, but should have only done so when users' emails a... |
| CVE-2020-25702 | MEDIUM | 6.1 | 1.3% | Nov 19, 2020 | In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. Thi... |
| CVE-2020-25701 | MEDIUM | 5.3 | 1.4% | Nov 19, 2020 | If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabl... |
| CVE-2020-25700 | MEDIUM | 6.5 | 1.3% | Nov 19, 2020 | In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versi... |
| CVE-2020-9049 | MEDIUM | 5.3 | 0.5% | Nov 19, 2020 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could ... |
| CVE-2020-4718 | MEDIUM | 5.4 | 0.6% | Nov 19, 2020 | IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerabili... |
| CVE-2020-15710 | MEDIUM | 6.1 | 0.3% | Nov 19, 2020 | Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. ... |
| CVE-2020-8278 | MEDIUM | 5.3 | 1.0% | Nov 19, 2020 | Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user. |
| CVE-2020-5947 | MEDIUM | 4.3 | 0.7% | Nov 19, 2020 | In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequenc... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now