2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28042 | MEDIUM | 5.3 | 2.3% | Nov 2, 2020 | ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken functio... |
| CVE-2020-28041 | MEDIUM | 6.5 | 2.0% | Nov 2, 2020 | The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate wi... |
| CVE-2020-28040 | MEDIUM | 4.3 | 1.1% | Nov 2, 2020 | WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. |
| CVE-2020-28038 | MEDIUM | 6.1 | 2.6% | Nov 2, 2020 | WordPress before 5.5.2 allows stored XSS via post slugs. |
| CVE-2020-28034 | MEDIUM | 6.1 | 1.7% | Nov 2, 2020 | WordPress before 5.5.2 allows XSS associated with global variables. |
| CVE-2020-28031 | MEDIUM | 4.3 | 0.6% | Nov 2, 2020 | eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenti... |
| CVE-2020-28002 | MEDIUM | 5.3 | 1.1% | Nov 2, 2020 | In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty val... |
| CVE-2020-27982 | MEDIUM | 6.1 | 5.3% | Nov 2, 2020 | IceWarp 11.4.5.0 allows XSS via the language parameter. |
| CVE-2020-27359 | MEDIUM | 5.4 | 0.8% | Nov 2, 2020 | A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScrip... |
| CVE-2020-27358 | MEDIUM | 4.3 | 2.0% | Nov 2, 2020 | An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export... |
| CVE-2020-25689 | MEDIUM | 6.5 | 1.5% | Nov 2, 2020 | A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in ... |
| CVE-2020-15914 | MEDIUM | 5.4 | 0.6% | Nov 2, 2020 | A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allo... |
| CVE-2020-27015 | MEDIUM | 4.4 | 0.9% | Oct 30, 2020 | Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exp... |
| CVE-2020-27014 | MEDIUM | 6.4 | 0.3% | Oct 30, 2020 | Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Block... |
| CVE-2020-27885 | MEDIUM | 6.1 | 0.9% | Oct 29, 2020 | Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability t... |
| CVE-2020-26205 | MEDIUM | 5.4 | 0.7% | Oct 29, 2020 | Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal throug... |
| CVE-2020-14323 | MEDIUM | 5.5 | 0.6% | Oct 29, 2020 | A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and befor... |
| CVE-2020-27747 | MEDIUM | 6.8 | 1.1% | Oct 29, 2020 | An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a... |
| CVE-2020-5935 | MEDIUM | 5.9 | 0.8% | Oct 29, 2020 | On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.... |
| CVE-2020-5934 | MEDIUM | 6.5 | 0.4% | Oct 29, 2020 | On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to... |
| CVE-2020-5932 | MEDIUM | 4.8 | 0.5% | Oct 29, 2020 | On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility... |
| CVE-2020-4864 | MEDIUM | 4.3 | 0.4% | Oct 29, 2020 | IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP... |
| CVE-2020-27993 | MEDIUM | 5.3 | 2.5% | Oct 29, 2020 | Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files. |
| CVE-2020-5938 | MEDIUM | 6.5 | 0.5% | Oct 29, 2020 | On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authent... |
| CVE-2020-21266 | MEDIUM | 6.1 | 0.6% | Oct 29, 2020 | Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now