2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5929 | MEDIUM | 5.9 | 1.2% | Sep 25, 2020 | In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware ac... |
| CVE-2020-25131 | MEDIUM | 6.1 | 0.8% | Sep 25, 2020 | An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scr... |
| CVE-2020-25130 | MEDIUM | 6.5 | 1.0% | Sep 25, 2020 | An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection ... |
| CVE-2020-15372 | MEDIUM | 5.5 | 0.3% | Sep 25, 2020 | A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v... |
| CVE-2020-15370 | MEDIUM | 6.5 | 1.0% | Sep 25, 2020 | Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user... |
| CVE-2020-7735 | MEDIUM | 6.6 | 2.4% | Sep 25, 2020 | The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option. |
| CVE-2020-15521 | MEDIUM | 6.1 | 1.7% | Sep 25, 2020 | Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripti... |
| CVE-2020-26115 | MEDIUM | 6.1 | 0.6% | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574). |
| CVE-2020-26114 | MEDIUM | 6.1 | 0.6% | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573). |
| CVE-2020-26113 | MEDIUM | 6.1 | 0.6% | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569). |
| CVE-2020-26111 | MEDIUM | 6.1 | 0.6% | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566). |
| CVE-2020-26110 | MEDIUM | 6.1 | 0.8% | Sep 25, 2020 | cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564). |
| CVE-2020-25625 | MEDIUM | 5.3 | 0.4% | Sep 25, 2020 | hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop. |
| CVE-2020-25085 | MEDIUM | 5 | 0.6% | Sep 25, 2020 | QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write... |
| CVE-2020-25203 | MEDIUM | 5.5 | 0.5% | Sep 25, 2020 | The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By cal... |
| CVE-2020-24615 | MEDIUM | 5.3 | 1.0% | Sep 25, 2020 | Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP. |
| CVE-2020-24595 | MEDIUM | 5.3 | 0.9% | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensit... |
| CVE-2020-24592 | MEDIUM | 5.3 | 0.9% | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system inf... |
| CVE-2020-15162 | MEDIUM | 5.4 | 0.8% | Sep 24, 2020 | In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attach... |
| CVE-2020-15161 | MEDIUM | 6.1 | 0.9% | Sep 24, 2020 | In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the c... |
| CVE-2020-8348 | MEDIUM | 6.1 | 1.0% | Sep 24, 2020 | A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1... |
| CVE-2020-8347 | MEDIUM | 6.1 | 1.1% | Sep 24, 2020 | A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.... |
| CVE-2020-15930 | MEDIUM | 6.1 | 4.4% | Sep 24, 2020 | An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. |
| CVE-2020-3524 | MEDIUM | 6.8 | 0.3% | Sep 24, 2020 | A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series Integrated Services Routers, Cis... |
| CVE-2020-3516 | MEDIUM | 4.3 | 1.7% | Sep 24, 2020 | A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now