2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2289 | MEDIUM | 5.4 | 0.9% | Oct 8, 2020 | Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in... |
| CVE-2020-2288 | MEDIUM | 5.3 | 0.9% | Oct 8, 2020 | In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by... |
| CVE-2020-2287 | MEDIUM | 5.3 | 1.2% | Oct 8, 2020 | Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths t... |
| CVE-2020-26567 | MEDIUM | 5.5 | 17.2% | Oct 8, 2020 | An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed ... |
| CVE-2020-25272 | MEDIUM | 6.1 | 0.9% | Oct 8, 2020 | In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php. |
| CVE-2020-25271 | MEDIUM | 5.4 | 0.6% | Oct 8, 2020 | PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appoin... |
| CVE-2020-25270 | MEDIUM | 5.4 | 3.1% | Oct 8, 2020 | PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o... |
| CVE-2020-25262 | MEDIUM | 4.3 | 0.5% | Oct 8, 2020 | PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted. |
| CVE-2020-3602 | MEDIUM | 6.7 | 0.4% | Oct 8, 2020 | A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticat... |
| CVE-2020-3601 | MEDIUM | 6.7 | 0.4% | Oct 8, 2020 | A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticat... |
| CVE-2020-3598 | MEDIUM | 6.5 | 0.9% | Oct 8, 2020 | A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenti... |
| CVE-2020-3597 | MEDIUM | 5.4 | 1.4% | Oct 8, 2020 | A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated,... |
| CVE-2020-3589 | MEDIUM | 4.8 | 0.6% | Oct 8, 2020 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an au... |
| CVE-2020-3568 | MEDIUM | 5.8 | 1.0% | Oct 8, 2020 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)... |
| CVE-2020-3567 | MEDIUM | 6.5 | 1.1% | Oct 8, 2020 | A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remo... |
| CVE-2020-3543 | MEDIUM | 6.5 | 0.4% | Oct 8, 2020 | A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauth... |
| CVE-2020-3536 | MEDIUM | 5.4 | 0.6% | Oct 8, 2020 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem... |
| CVE-2020-3320 | MEDIUM | 5.4 | 0.6% | Oct 8, 2020 | A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated,... |
| CVE-2020-15501 | MEDIUM | 6.5 | 1.1% | Oct 7, 2020 | Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User int... |
| CVE-2020-25867 | MEDIUM | 5.3 | 2.8% | Oct 7, 2020 | SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to ... |
| CVE-2020-25768 | MEDIUM | 5.3 | 0.8% | Oct 7, 2020 | Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inj... |
| CVE-2020-15226 | MEDIUM | 4.3 | 1.0% | Oct 7, 2020 | In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break th... |
| CVE-2020-26164 | MEDIUM | 5.5 | 0.5% | Oct 7, 2020 | In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that tri... |
| CVE-2020-15217 | MEDIUM | 5.3 | 1.0% | Oct 7, 2020 | In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in... |
| CVE-2020-15177 | MEDIUM | 6.1 | 0.8% | Oct 7, 2020 | In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now