2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26134 | MEDIUM | 6.1 | 1.1% | Oct 2, 2020 | Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode. |
| CVE-2020-17482 | MEDIUM | 4.3 | 2.6% | Oct 2, 2020 | An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to inser... |
| CVE-2020-14294 | MEDIUM | 6.1 | 1.2% | Oct 2, 2020 | An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when re... |
| CVE-2020-13168 | MEDIUM | 6.1 | 1.0% | Oct 2, 2020 | SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter. |
| CVE-2020-26536 | MEDIUM | 5.5 | 0.9% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PD... |
| CVE-2020-26524 | MEDIUM | 5.3 | 1.4% | Oct 2, 2020 | CodeLathe FileCloud before 20.2.0.11915 allows username enumeration. |
| CVE-2020-26523 | MEDIUM | 6.1 | 0.7% | Oct 2, 2020 | Froala Editor before 3.2.2 allows XSS via pasted content. |
| CVE-2020-26519 | MEDIUM | 5.5 | 1.0% | Oct 2, 2020 | Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a de... |
| CVE-2020-5789 | MEDIUM | 6.5 | 1.3% | Oct 1, 2020 | Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the cont... |
| CVE-2020-5788 | MEDIUM | 6.5 | 1.2% | Oct 1, 2020 | Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitr... |
| CVE-2020-5787 | MEDIUM | 6.5 | 1.6% | Oct 1, 2020 | Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitr... |
| CVE-2020-5785 | MEDIUM | 6.1 | 0.7% | Oct 1, 2020 | Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct r... |
| CVE-2020-5784 | MEDIUM | 6.5 | 0.7% | Oct 1, 2020 | Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the applicatio... |
| CVE-2020-5387 | MEDIUM | 4.4 | 0.3% | Oct 1, 2020 | Dell XPS 13 9370 BIOS versions prior to 1.13.1 contains an Improper Exception Handling vulnerability. A local attacker w... |
| CVE-2020-14223 | MEDIUM | 6.1 | 0.6% | Oct 1, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed i... |
| CVE-2020-13940 | MEDIUM | 5.5 | 1.9% | Oct 1, 2020 | In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider o... |
| CVE-2020-15677 | MEDIUM | 6.1 | 1.6% | Oct 1, 2020 | By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the down... |
| CVE-2020-15676 | MEDIUM | 6.1 | 1.6% | Oct 1, 2020 | Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScr... |
| CVE-2020-15668 | MEDIUM | 4.3 | 0.5% | Oct 1, 2020 | A lock was missing when accessing a data structure and importing certificate information into the trust database. This v... |
| CVE-2020-15666 | MEDIUM | 6.5 | 1.2% | Oct 1, 2020 | When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was... |
| CVE-2020-15665 | MEDIUM | 4.3 | 0.7% | Oct 1, 2020 | Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. T... |
| CVE-2020-15664 | MEDIUM | 6.5 | 1.4% | Oct 1, 2020 | By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access t... |
| CVE-2020-25200 | MEDIUM | 5.3 | 7.5% | Oct 1, 2020 | Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Ini... |
| CVE-2020-15228 | MEDIUM | 5 | 1.4% | Oct 1, 2020 | In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Act... |
| CVE-2020-16844 | MEDIUM | 6.8 | 1.1% | Oct 1, 2020 | In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now