2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17458 | MEDIUM | 5.4 | 0.6% | Sep 2, 2020 | A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field. |
| CVE-2020-25073 | MEDIUM | 5.3 | 2.1% | Sep 2, 2020 | FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apa... |
| CVE-2020-8335 | MEDIUM | 6.8 | 0.3% | Sep 1, 2020 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS ... |
| CVE-2020-6873 | MEDIUM | 5.3 | 1.3% | Sep 1, 2020 | A ZTE product has a DoS vulnerability. Because the equipment couldn’t distinguish the attack packets and normal packets ... |
| CVE-2020-13946 | MEDIUM | 5.9 | 3.0% | Sep 1, 2020 | In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local atta... |
| CVE-2020-23839 | MEDIUM | 6.1 | 10.5% | Sep 1, 2020 | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa... |
| CVE-2020-23835 | MEDIUM | 6.1 | 2.3% | Sep 1, 2020 | A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Mana... |
| CVE-2020-23831 | MEDIUM | 6.1 | 0.8% | Sep 1, 2020 | A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Manag... |
| CVE-2020-23450 | MEDIUM | 5.4 | 0.8% | Sep 1, 2020 | Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS... |
| CVE-2020-2251 | MEDIUM | 4.3 | 0.5% | Sep 1, 2020 | Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain t... |
| CVE-2020-2250 | MEDIUM | 6.5 | 0.6% | Sep 1, 2020 | Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml file... |
| CVE-2020-2248 | MEDIUM | 6.1 | 0.9% | Sep 1, 2020 | Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (X... |
| CVE-2020-2247 | MEDIUM | 6.5 | 0.8% | Sep 1, 2020 | Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (... |
| CVE-2020-2246 | MEDIUM | 5.4 | 0.8% | Sep 1, 2020 | Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-si... |
| CVE-2020-2244 | MEDIUM | 5.4 | 0.8% | Sep 1, 2020 | Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, re... |
| CVE-2020-2243 | MEDIUM | 5.4 | 0.8% | Sep 1, 2020 | Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored ... |
| CVE-2020-2242 | MEDIUM | 6.5 | 0.7% | Sep 1, 2020 | A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenki... |
| CVE-2020-2239 | MEDIUM | 4.3 | 0.5% | Sep 1, 2020 | Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration fi... |
| CVE-2020-2238 | MEDIUM | 5.4 | 0.8% | Sep 1, 2020 | Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page... |
| CVE-2020-14514 | MEDIUM | 4.3 | 0.5% | Sep 1, 2020 | All trailer Power Line Communications are affected. PLC bus traffic can be sniffed reliably via an active antenna up to ... |
| CVE-2020-15704 | MEDIUM | 5.5 | 0.4% | Sep 1, 2020 | The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module load... |
| CVE-2020-25048 | MEDIUM | 4.6 | 0.2% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Q... |
| CVE-2020-25047 | MEDIUM | 5.5 | 0.1% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software. The S ... |
| CVE-2020-25046 | MEDIUM | 5.5 | 0.1% | Aug 31, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks addres... |
| CVE-2020-14364 | MEDIUM | 5 | 5.4% | Aug 31, 2020 | An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now