2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17551 | MEDIUM | 4.8 | 1.1% | Oct 7, 2020 | ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution. |
| CVE-2020-26870 | MEDIUM | 6.1 | 4.5% | Oct 7, 2020 | Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily... |
| CVE-2020-24722 | MEDIUM | 5.9 | 2.4% | Oct 7, 2020 | An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in CO... |
| CVE-2020-14355 | MEDIUM | 6.6 | 2.5% | Oct 7, 2020 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display syste... |
| CVE-2020-25343 | MEDIUM | 5.4 | 0.7% | Oct 7, 2020 | Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script o... |
| CVE-2020-13346 | MEDIUM | 6.5 | 1.3% | Oct 7, 2020 | Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allow... |
| CVE-2020-13335 | MEDIUM | 4.3 | 0.8% | Oct 7, 2020 | Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account w... |
| CVE-2020-14183 | MEDIUM | 4.3 | 1.3% | Oct 6, 2020 | Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jir... |
| CVE-2020-26603 | MEDIUM | 5.3 | 0.5% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows direc... |
| CVE-2020-26599 | MEDIUM | 5.3 | 0.3% | Oct 6, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can ... |
| CVE-2020-13345 | MEDIUM | 5.4 | 0.9% | Oct 6, 2020 | An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes |
| CVE-2020-13333 | MEDIUM | 4.3 | 2.1% | Oct 6, 2020 | A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a lin... |
| CVE-2020-1904 | MEDIUM | 5.5 | 1.1% | Oct 6, 2020 | A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have... |
| CVE-2020-1903 | MEDIUM | 5.5 | 0.7% | Oct 6, 2020 | An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for i... |
| CVE-2020-1901 | MEDIUM | 5.3 | 1.0% | Oct 6, 2020 | Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application... |
| CVE-2020-15215 | MEDIUM | 5.6 | 0.7% | Oct 6, 2020 | Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using b... |
| CVE-2020-4528 | MEDIUM | 5.5 | 0.3% | Oct 6, 2020 | IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under spe... |
| CVE-2020-25641 | MEDIUM | 5.5 | 0.4% | Oct 6, 2020 | A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec reques... |
| CVE-2020-25637 | MEDIUM | 6.7 | 0.5% | Oct 6, 2020 | A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting i... |
| CVE-2020-25986 | MEDIUM | 6.5 | 0.6% | Oct 6, 2020 | A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user. |
| CVE-2020-23832 | MEDIUM | 6.1 | 2.1% | Oct 6, 2020 | A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System... |
| CVE-2020-5631 | MEDIUM | 6.1 | 1.0% | Oct 6, 2020 | Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arb... |
| CVE-2020-26572 | MEDIUM | 5.5 | 0.4% | Oct 6, 2020 | The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher. |
| CVE-2020-26571 | MEDIUM | 5.5 | 0.4% | Oct 6, 2020 | The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu... |
| CVE-2020-26570 | MEDIUM | 5.5 | 0.4% | Oct 6, 2020 | The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now