2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-24855MEDIUM5.3Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via c...
CVE-2020-21219MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remo...
CVE-2020-20589MEDIUM6.1Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang at...
CVE-2020-4497MEDIUM5.9 IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in ...
CVE-2020-9420MEDIUM6.5The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allow...
CVE-2020-9419MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Arcadyan Wifi routers VRV9506JAC23 allow remote attackers ...
CVE-2020-36609MEDIUM5.4A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of...
CVE-2020-36565MEDIUM5.3Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing ...
CVE-2020-23590MEDIUM6.5A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenti...
CVE-2020-23589MEDIUM6.5A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenti...
CVE-2020-23588MEDIUM4.3A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenti...
CVE-2020-23586MEDIUM4.3A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unau...
CVE-2020-23593MEDIUM6.5A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthentic...
CVE-2020-23582MEDIUM6.5A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, r...
CVE-2020-35473MEDIUM4.3An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifica...
CVE-2020-36608MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this iss...
CVE-2020-36605MEDIUM4.4Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe compon...
CVE-2020-5355MEDIUM4.3The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and ...
CVE-2020-9285MEDIUM6.8Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware...
CVE-2020-15853MEDIUM5.3supybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a whil...
CVE-2020-15855MEDIUM6.1Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.
CVE-2020-15346MEDIUM5.3Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.
CVE-2020-15345MEDIUM5.3Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
CVE-2020-15344MEDIUM5.3Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
CVE-2020-15343MEDIUM5.3Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now