2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26917 | MEDIUM | 4.8 | 0.6% | Oct 9, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 be... |
| CVE-2020-26916 | MEDIUM | 6.3 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6200 before 1.1.00.3... |
| CVE-2020-26915 | MEDIUM | 4.8 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-26913 | MEDIUM | 6.8 | 0.6% | Oct 9, 2020 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor... |
| CVE-2020-26910 | MEDIUM | 6.8 | 1.0% | Oct 9, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, ... |
| CVE-2020-26901 | MEDIUM | 6.5 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK752 before 3.2.15.25, RBR75... |
| CVE-2020-26899 | MEDIUM | 6.5 | 0.8% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.10, RBK752 ... |
| CVE-2020-26162 | MEDIUM | 6.1 | 0.6% | Oct 9, 2020 | Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description p... |
| CVE-2020-13626 | MEDIUM | 4.6 | 0.3% | Oct 9, 2020 | OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authori... |
| CVE-2020-15241 | MEDIUM | 6.1 | 1.0% | Oct 8, 2020 | TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vul... |
| CVE-2020-15242 | MEDIUM | 6.1 | 0.8% | Oct 8, 2020 | Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the t... |
| CVE-2020-5389 | MEDIUM | 6.5 | 0.9% | Oct 8, 2020 | Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain... |
| CVE-2020-24301 | MEDIUM | 6.1 | 0.9% | Oct 8, 2020 | Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability ... |
| CVE-2020-15646 | MEDIUM | 5.9 | 0.9% | Oct 8, 2020 | If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange ... |
| CVE-2020-13344 | MEDIUM | 4.4 | 0.3% | Oct 8, 2020 | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Sessions keys are sto... |
| CVE-2020-13339 | MEDIUM | 6.5 | 0.8% | Oct 8, 2020 | An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview... |
| CVE-2020-12401 | MEDIUM | 4.7 | 0.3% | Oct 8, 2020 | During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication w... |
| CVE-2020-12400 | MEDIUM | 4.7 | 0.3% | Oct 8, 2020 | When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulti... |
| CVE-2020-2298 | MEDIUM | 6.5 | 1.1% | Oct 8, 2020 | Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attac... |
| CVE-2020-2296 | MEDIUM | 4.3 | 0.8% | Oct 8, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to ... |
| CVE-2020-2295 | MEDIUM | 6.5 | 0.5% | Oct 8, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attac... |
| CVE-2020-2294 | MEDIUM | 6.5 | 0.8% | Oct 8, 2020 | Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, all... |
| CVE-2020-2293 | MEDIUM | 6.5 | 1.0% | Oct 8, 2020 | Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins ... |
| CVE-2020-2292 | MEDIUM | 5.4 | 0.7% | Oct 8, 2020 | Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cr... |
| CVE-2020-2290 | MEDIUM | 5.4 | 0.9% | Oct 8, 2020 | Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Refer... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now