2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25864 | MEDIUM | 6.1 | 6.1% | Apr 20, 2021 | HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scriptin... |
| CVE-2020-14105 | MEDIUM | 5.5 | 0.3% | Apr 20, 2021 | The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15. |
| CVE-2020-7856 | CRITICAL | 9.8 | 0.9% | Apr 20, 2021 | A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exis... |
| CVE-2020-27241 | CRITICAL | 9.8 | 0.9% | Apr 19, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber par... |
| CVE-2020-27240 | CRITICAL | 9.8 | 0.9% | Apr 19, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus ... |
| CVE-2020-28141 | MEDIUM | 5.4 | 0.6% | Apr 19, 2021 | The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated us... |
| CVE-2020-7851 | HIGH | 7.8 | 0.7% | Apr 19, 2021 | Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could ... |
| CVE-2020-36195 | CRITICAL | 9.8 | 1.8% | Apr 17, 2021 | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming ad... |
| CVE-2020-2509 | CRITICAL | 9.8 | 34.2% | Apr 17, 2021 | A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows... |
| CVE-2020-9681 | MEDIUM | 6.5 | 0.7% | Apr 16, 2021 | Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut... |
| CVE-2020-9668 | HIGH | 7.8 | 1.6% | Apr 16, 2021 | Adobe Genuine Service version 6.6 (and earlier) is affected by an Improper Access control vulnerability when handling sy... |
| CVE-2020-9667 | MEDIUM | 6.5 | 0.5% | Apr 16, 2021 | Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut... |
| CVE-2020-28898 | MEDIUM | 5.3 | 1.3% | Apr 15, 2021 | In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a ... |
| CVE-2020-28593 | HIGH | 8.1 | 1.9% | Apr 15, 2021 | A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF... |
| CVE-2020-28592 | CRITICAL | 9.8 | 2.5% | Apr 15, 2021 | A heap-based buffer overflow vulnerability exists in the configuration server functionality of the Cosori Smart 5.8-Quar... |
| CVE-2020-27239 | CRITICAL | 9.8 | 0.9% | Apr 15, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus para... |
| CVE-2020-27238 | CRITICAL | 9.8 | 0.9% | Apr 15, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter i... |
| CVE-2020-27237 | CRITICAL | 9.8 | 0.9% | Apr 15, 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter i... |
| CVE-2020-7308 | MEDIUM | 6.5 | 0.5% | Apr 15, 2021 | Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Febru... |
| CVE-2020-7270 | MEDIUM | 4.3 | 0.8% | Apr 15, 2021 | Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re... |
| CVE-2020-7269 | MEDIUM | 4.3 | 0.7% | Apr 15, 2021 | Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re... |
| CVE-2020-36288 | MEDIUM | 6.1 | 1.5% | Apr 15, 2021 | The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before ver... |
| CVE-2020-35660 | MEDIUM | 5.4 | 0.9% | Apr 14, 2021 | Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page. |
| CVE-2020-28124 | MEDIUM | 5.4 | 0.5% | Apr 14, 2021 | Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field. |
| CVE-2020-35419 | MEDIUM | 6.1 | 0.7% | Apr 14, 2021 | Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now