2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16140 | MEDIUM | 6.1 | 0.9% | Oct 27, 2020 | The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS. |
| CVE-2020-9982 | MEDIUM | 5.5 | 0.8% | Oct 27, 2020 | This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 ... |
| CVE-2020-9979 | MEDIUM | 5.5 | 0.4% | Oct 27, 2020 | A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An att... |
| CVE-2020-9860 | MEDIUM | 5.4 | 1.0% | Oct 27, 2020 | A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 13.0.5. P... |
| CVE-2020-9857 | MEDIUM | 4.3 | 0.8% | Oct 27, 2020 | An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in... |
| CVE-2020-3852 | MEDIUM | 5.3 | 1.0% | Oct 27, 2020 | A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrec... |
| CVE-2020-6022 | MEDIUM | 5.5 | 0.3% | Oct 27, 2020 | Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files... |
| CVE-2020-27182 | MEDIUM | 6.1 | 0.8% | Oct 27, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to in... |
| CVE-2020-27181 | MEDIUM | 6.5 | 0.9% | Oct 27, 2020 | A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to c... |
| CVE-2020-25034 | MEDIUM | 6.5 | 1.4% | Oct 26, 2020 | eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via th... |
| CVE-2020-15274 | MEDIUM | 5.4 | 0.8% | Oct 26, 2020 | In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. W... |
| CVE-2020-26161 | MEDIUM | 6.1 | 1.1% | Oct 26, 2020 | In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header... |
| CVE-2020-7196 | MEDIUM | 6.5 | 0.9% | Oct 26, 2020 | The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of han... |
| CVE-2020-7126 | MEDIUM | 5.8 | 0.8% | Oct 26, 2020 | A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to ... |
| CVE-2020-6876 | MEDIUM | 5.4 | 0.6% | Oct 26, 2020 | A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of cl... |
| CVE-2020-25470 | MEDIUM | 6.1 | 1.3% | Oct 26, 2020 | AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added sit... |
| CVE-2020-27388 | MEDIUM | 5.4 | 0.8% | Oct 23, 2020 | Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An au... |
| CVE-2020-24847 | MEDIUM | 4.3 | 0.4% | Oct 23, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protect... |
| CVE-2020-3998 | MEDIUM | 6.5 | 1.3% | Oct 23, 2020 | VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious att... |
| CVE-2020-3997 | MEDIUM | 5.4 | 0.7% | Oct 23, 2020 | VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful ex... |
| CVE-2020-9361 | MEDIUM | 5.5 | 0.4% | Oct 23, 2020 | CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause... |
| CVE-2020-15004 | MEDIUM | 4.8 | 2.8% | Oct 23, 2020 | OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS. |
| CVE-2020-15003 | MEDIUM | 4.3 | 0.8% | Oct 23, 2020 | OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string o... |
| CVE-2020-15002 | MEDIUM | 5 | 1.6% | Oct 23, 2020 | OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. |
| CVE-2020-15270 | MEDIUM | 4.3 | 1.2% | Oct 22, 2020 | Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid.... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now