2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24855 | MEDIUM | 5.3 | 1.0% | Dec 15, 2022 | Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via c... |
| CVE-2020-21219 | MEDIUM | 6.1 | 0.6% | Dec 15, 2022 | Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remo... |
| CVE-2020-20589 | MEDIUM | 6.1 | 0.6% | Dec 15, 2022 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang at... |
| CVE-2020-4497 | MEDIUM | 5.9 | 0.4% | Dec 14, 2022 | IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in ... |
| CVE-2020-9420 | MEDIUM | 6.5 | 0.5% | Dec 14, 2022 | The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allow... |
| CVE-2020-9419 | MEDIUM | 5.4 | 0.5% | Dec 14, 2022 | Multiple stored cross-site scripting (XSS) vulnerabilities in Arcadyan Wifi routers VRV9506JAC23 allow remote attackers ... |
| CVE-2020-36609 | MEDIUM | 5.4 | 0.4% | Dec 8, 2022 | A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of... |
| CVE-2020-36565 | MEDIUM | 5.3 | 1.3% | Dec 7, 2022 | Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing ... |
| CVE-2020-23590 | MEDIUM | 6.5 | 0.4% | Nov 23, 2022 | A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenti... |
| CVE-2020-23589 | MEDIUM | 6.5 | 0.5% | Nov 23, 2022 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenti... |
| CVE-2020-23588 | MEDIUM | 4.3 | 0.4% | Nov 23, 2022 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenti... |
| CVE-2020-23586 | MEDIUM | 4.3 | 0.4% | Nov 23, 2022 | A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unau... |
| CVE-2020-23593 | MEDIUM | 6.5 | 0.4% | Nov 23, 2022 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthentic... |
| CVE-2020-23582 | MEDIUM | 6.5 | 0.4% | Nov 21, 2022 | A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, r... |
| CVE-2020-35473 | MEDIUM | 4.3 | 0.3% | Nov 8, 2022 | An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifica... |
| CVE-2020-36608 | MEDIUM | 6.1 | 0.4% | Nov 2, 2022 | A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this iss... |
| CVE-2020-36605 | MEDIUM | 4.4 | 0.1% | Nov 1, 2022 | Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe compon... |
| CVE-2020-5355 | MEDIUM | 4.3 | 0.4% | Oct 21, 2022 | The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and ... |
| CVE-2020-9285 | MEDIUM | 6.8 | 0.5% | Oct 20, 2022 | Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware... |
| CVE-2020-15853 | MEDIUM | 5.3 | 0.6% | Oct 18, 2022 | supybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a whil... |
| CVE-2020-15855 | MEDIUM | 6.1 | 0.4% | Oct 7, 2022 | Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1. |
| CVE-2020-15346 | MEDIUM | 5.3 | 0.6% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key. |
| CVE-2020-15345 | MEDIUM | 5.3 | 0.6% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API. |
| CVE-2020-15344 | MEDIUM | 5.3 | 0.6% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API. |
| CVE-2020-15343 | MEDIUM | 5.3 | 0.6% | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now