2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25516 | MEDIUM | 5.4 | 0.6% | Oct 29, 2020 | WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer ... |
| CVE-2020-27658 | MEDIUM | 6.1 | 1.3% | Oct 29, 2020 | Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the sessio... |
| CVE-2020-27657 | MEDIUM | 5.9 | 0.6% | Oct 29, 2020 | Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081... |
| CVE-2020-11488 | MEDIUM | 6.7 | 0.2% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior... |
| CVE-2020-11484 | MEDIUM | 4.9 | 1.1% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmw... |
| CVE-2020-24712 | MEDIUM | 5.4 | 0.9% | Oct 28, 2020 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page. |
| CVE-2020-24711 | MEDIUM | 6.5 | 1.5% | Oct 28, 2020 | The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via... |
| CVE-2020-24710 | MEDIUM | 5.3 | 1.3% | Oct 28, 2020 | Gophish before 0.11.0 allows SSRF attacks. |
| CVE-2020-24709 | MEDIUM | 5.4 | 0.5% | Oct 28, 2020 | Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template. |
| CVE-2020-24708 | MEDIUM | 5.4 | 0.6% | Oct 28, 2020 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form. |
| CVE-2020-27980 | MEDIUM | 5.4 | 0.6% | Oct 28, 2020 | Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to... |
| CVE-2020-27742 | MEDIUM | 6.5 | 1.1% | Oct 28, 2020 | An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to... |
| CVE-2020-27741 | MEDIUM | 6.1 | 0.8% | Oct 28, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbit... |
| CVE-2020-27740 | MEDIUM | 5.3 | 1.3% | Oct 28, 2020 | Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. NOTE: t... |
| CVE-2020-25204 | MEDIUM | 5.5 | 0.4% | Oct 28, 2020 | The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.fronte... |
| CVE-2020-16261 | MEDIUM | 6.8 | 0.5% | Oct 28, 2020 | Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access. |
| CVE-2020-4782 | MEDIUM | 6.5 | 2.5% | Oct 28, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys... |
| CVE-2020-27974 | MEDIUM | 6.1 | 0.7% | Oct 28, 2020 | NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS. |
| CVE-2020-24303 | MEDIUM | 6.1 | 1.8% | Oct 28, 2020 | Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. |
| CVE-2020-8263 | MEDIUM | 5.4 | 0.7% | Oct 28, 2020 | A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct... |
| CVE-2020-8262 | MEDIUM | 6.1 | 1.8% | Oct 28, 2020 | A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Sit... |
| CVE-2020-8261 | MEDIUM | 4.3 | 2.1% | Oct 28, 2020 | A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection. |
| CVE-2020-8255 | MEDIUM | 4.9 | 2.3% | Oct 28, 2020 | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform... |
| CVE-2020-6829 | MEDIUM | 5.3 | 1.4% | Oct 28, 2020 | When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial i... |
| CVE-2020-27957 | MEDIUM | 5.4 | 0.6% | Oct 28, 2020 | The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certa... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now