2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28900 | CRITICAL | 9.8 | 2.4% | May 24, 2021 | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows... |
| CVE-2020-26006 | MEDIUM | 6.1 | 0.7% | May 24, 2021 | Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php. |
| CVE-2020-25411 | MEDIUM | 6.5 | 0.7% | May 24, 2021 | Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing... |
| CVE-2020-25409 | CRITICAL | 9.8 | 1.6% | May 24, 2021 | Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. |
| CVE-2020-25408 | MEDIUM | 6.5 | 0.8% | May 24, 2021 | A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows ... |
| CVE-2020-23768 | HIGH | 7.5 | 1.0% | May 21, 2021 | An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interfa... |
| CVE-2020-23766 | MEDIUM | 6.5 | 1.4% | May 21, 2021 | An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolut... |
| CVE-2020-23765 | HIGH | 7.2 | 1.1% | May 21, 2021 | A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If a... |
| CVE-2020-36332 | HIGH | 7.5 | 2.0% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memor... |
| CVE-2020-36331 | CRITICAL | 9.1 | 2.3% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The h... |
| CVE-2020-36330 | CRITICAL | 9.1 | 2.2% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. ... |
| CVE-2020-36329 | CRITICAL | 9.8 | 2.3% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early.... |
| CVE-2020-36328 | CRITICAL | 9.8 | 2.7% | May 21, 2021 | A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is poss... |
| CVE-2020-27211 | MEDIUM | 5.7 | 0.3% | May 21, 2021 | Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The fl... |
| CVE-2020-27212 | HIGH | 7 | 0.3% | May 21, 2021 | STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP)... |
| CVE-2020-27208 | MEDIUM | 6.8 | 0.3% | May 21, 2021 | The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.... |
| CVE-2020-12061 | CRITICAL | 9.8 | 1.9% | May 21, 2021 | An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the sec... |
| CVE-2020-27209 | HIGH | 7.5 | 1.5% | May 20, 2021 | The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversar... |
| CVE-2020-18220 | HIGH | 7.5 | 0.4% | May 20, 2021 | Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not... |
| CVE-2020-21345 | MEDIUM | 6.1 | 0.8% | May 20, 2021 | Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a rem... |
| CVE-2020-35580 | HIGH | 7.5 | 14.0% | May 20, 2021 | A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated us... |
| CVE-2020-21057 | HIGH | 8.1 | 1.5% | May 20, 2021 | Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the syst... |
| CVE-2020-21056 | MEDIUM | 4.3 | 1.0% | May 20, 2021 | Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via ... |
| CVE-2020-21055 | MEDIUM | 6.5 | 1.2% | May 20, 2021 | A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.vi... |
| CVE-2020-21054 | MEDIUM | 6.1 | 0.7% | May 20, 2021 | Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now