2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24977 | MEDIUM | 6.5 | 3.7% | Sep 4, 2020 | GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entiti... |
| CVE-2020-9235 | MEDIUM | 5.5 | 0.2% | Sep 3, 2020 | Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2)... |
| CVE-2020-9199 | MEDIUM | 6.8 | 0.8% | Sep 3, 2020 | B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with ... |
| CVE-2020-25124 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI. |
| CVE-2020-25123 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager. |
| CVE-2020-25122 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager. |
| CVE-2020-25121 | MEDIUM | 4.8 | 0.7% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options. |
| CVE-2020-25120 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI. |
| CVE-2020-25119 | MEDIUM | 4.8 | 0.7% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual. |
| CVE-2020-25118 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager. |
| CVE-2020-25117 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager. |
| CVE-2020-25116 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager. |
| CVE-2020-25115 | MEDIUM | 4.8 | 0.6% | Sep 3, 2020 | The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager. |
| CVE-2020-14373 | MEDIUM | 5.5 | 0.5% | Sep 3, 2020 | A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a s... |
| CVE-2020-10720 | MEDIUM | 5.5 | 0.3% | Sep 3, 2020 | A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with l... |
| CVE-2020-25102 | MEDIUM | 6.1 | 0.9% | Sep 3, 2020 | silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-S... |
| CVE-2020-23814 | MEDIUM | 6.1 | 1.2% | Sep 3, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web scr... |
| CVE-2020-25104 | MEDIUM | 5.4 | 0.6% | Sep 3, 2020 | eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For exam... |
| CVE-2020-24863 | MEDIUM | 5.5 | 0.5% | Sep 3, 2020 | A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 th... |
| CVE-2020-24385 | MEDIUM | 5.5 | 0.4% | Sep 3, 2020 | In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in th... |
| CVE-2020-13972 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the ... |
| CVE-2020-7382 | MEDIUM | 6.5 | 0.3% | Sep 3, 2020 | Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the loc... |
| CVE-2020-4337 | MEDIUM | 6.5 | 1.1% | Sep 3, 2020 | IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server... |
| CVE-2020-12058 | MEDIUM | 6.1 | 1.0% | Sep 3, 2020 | Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary Ja... |
| CVE-2020-25093 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now