2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36387 | HIGH | 7.8 | 0.4% | Jun 7, 2021 | An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_fu... |
| CVE-2020-36386 | HIGH | 7.1 | 0.5% | Jun 7, 2021 | An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci... |
| CVE-2020-1742 | HIGH | 7 | 0.3% | Jun 7, 2021 | An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacke... |
| CVE-2020-1690 | MEDIUM | 6.5 | 0.2% | Jun 7, 2021 | An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root... |
| CVE-2020-18268 | MEDIUM | 6.1 | 2.7% | Jun 7, 2021 | Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect"... |
| CVE-2020-18265 | HIGH | 8.8 | 1.1% | Jun 7, 2021 | Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary cod... |
| CVE-2020-18264 | HIGH | 8.8 | 1.1% | Jun 7, 2021 | Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary cod... |
| CVE-2020-1719 | MEDIUM | 5.4 | 0.6% | Jun 7, 2021 | A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Se... |
| CVE-2020-5008 | MEDIUM | 5.3 | 0.9% | Jun 7, 2021 | IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET r... |
| CVE-2020-36385 | HIGH | 7.8 | 1.5% | Jun 7, 2021 | An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the... |
| CVE-2020-36384 | MEDIUM | 6.1 | 0.8% | Jun 7, 2021 | PageLayer before 1.3.5 allows reflected XSS via color settings. |
| CVE-2020-36383 | MEDIUM | 6.1 | 0.8% | Jun 7, 2021 | PageLayer before 1.3.5 allows reflected XSS via the font-size parameter. |
| CVE-2020-26885 | MEDIUM | 6.1 | 1.1% | Jun 7, 2021 | An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an ... |
| CVE-2020-29324 | HIGH | 7.5 | 1.1% | Jun 4, 2021 | The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation o... |
| CVE-2020-29323 | HIGH | 7.5 | 1.4% | Jun 4, 2021 | The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decom... |
| CVE-2020-29322 | HIGH | 7.5 | 1.7% | Jun 4, 2021 | The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmw... |
| CVE-2020-29321 | HIGH | 7.5 | 1.4% | Jun 4, 2021 | The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmw... |
| CVE-2020-36142 | MEDIUM | 6.5 | 1.4% | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. |
| CVE-2020-36141 | HIGH | 8.8 | 1.3% | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpe... |
| CVE-2020-36140 | MEDIUM | 6.5 | 0.6% | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of '... |
| CVE-2020-36139 | MEDIUM | 5.4 | 0.5% | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'file... |
| CVE-2020-27302 | HIGH | 8 | 2.0% | Jun 4, 2021 | A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "me... |
| CVE-2020-27301 | HIGH | 8 | 2.0% | Jun 4, 2021 | A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AE... |
| CVE-2020-7469 | HIGH | 7.5 | 1.2% | Jun 4, 2021 | In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 1... |
| CVE-2020-36382 | HIGH | 7.5 | 1.9% | Jun 4, 2021 | OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase v... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now