2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20628 | MEDIUM | 6.1 | 0.9% | Aug 31, 2020 | controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS. |
| CVE-2020-24699 | MEDIUM | 6.1 | 1.0% | Aug 31, 2020 | The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS. |
| CVE-2020-20627 | MEDIUM | 5.3 | 1.9% | Aug 31, 2020 | The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauth... |
| CVE-2020-20626 | MEDIUM | 5.4 | 0.8% | Aug 31, 2020 | lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS. |
| CVE-2020-17465 | MEDIUM | 6.1 | 0.7% | Aug 31, 2020 | Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vuln... |
| CVE-2020-13828 | MEDIUM | 5.4 | 0.8% | Aug 31, 2020 | Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authen... |
| CVE-2020-13472 | MEDIUM | 4.6 | 0.4% | Aug 31, 2020 | The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the... |
| CVE-2020-13471 | MEDIUM | 6.8 | 0.6% | Aug 31, 2020 | Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a spec... |
| CVE-2020-13470 | MEDIUM | 4.6 | 0.4% | Aug 31, 2020 | Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible b... |
| CVE-2020-13469 | MEDIUM | 4.6 | 0.4% | Aug 31, 2020 | The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via th... |
| CVE-2020-13468 | MEDIUM | 6.8 | 0.5% | Aug 31, 2020 | Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection i... |
| CVE-2020-13467 | MEDIUM | 4.6 | 0.3% | Aug 31, 2020 | The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attacker... |
| CVE-2020-13466 | MEDIUM | 6.8 | 0.4% | Aug 31, 2020 | STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power g... |
| CVE-2020-13465 | MEDIUM | 6.8 | 0.5% | Aug 31, 2020 | The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execut... |
| CVE-2020-13464 | MEDIUM | 4.2 | 0.2% | Aug 31, 2020 | The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attacker... |
| CVE-2020-13463 | MEDIUM | 4.6 | 0.3% | Aug 31, 2020 | The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firm... |
| CVE-2020-5419 | MEDIUM | 6.7 | 0.5% | Aug 31, 2020 | RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allow... |
| CVE-2020-13655 | MEDIUM | 6.1 | 0.7% | Aug 31, 2020 | An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is s... |
| CVE-2020-13595 | MEDIUM | 6.5 | 0.9% | Aug 31, 2020 | The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) return... |
| CVE-2020-13594 | MEDIUM | 6.5 | 0.8% | Aug 31, 2020 | The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does n... |
| CVE-2020-12646 | MEDIUM | 5.4 | 0.5% | Aug 31, 2020 | OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. |
| CVE-2020-12644 | MEDIUM | 5 | 0.7% | Aug 31, 2020 | OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API. |
| CVE-2020-12643 | MEDIUM | 4.3 | 0.6% | Aug 31, 2020 | OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing ... |
| CVE-2020-11617 | MEDIUM | 5.9 | 0.4% | Aug 31, 2020 | The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the S... |
| CVE-2020-4492 | MEDIUM | 5.5 | 0.3% | Aug 31, 2020 | IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a deni... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now