2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24008 | MEDIUM | 5.3 | 0.9% | Aug 26, 2020 | Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in me... |
| CVE-2020-19007 | MEDIUM | 5.4 | 0.5% | Aug 26, 2020 | Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code suppl... |
| CVE-2020-24314 | MEDIUM | 6.1 | 0.9% | Aug 26, 2020 | Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoin... |
| CVE-2020-24313 | MEDIUM | 6.1 | 1.2% | Aug 26, 2020 | Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the valu... |
| CVE-2020-15499 | MEDIUM | 6.1 | 0.6% | Aug 26, 2020 | An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on... |
| CVE-2020-15498 | MEDIUM | 5.9 | 0.4% | Aug 26, 2020 | An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server cert... |
| CVE-2020-16193 | MEDIUM | 5.4 | 0.6% | Aug 26, 2020 | osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call. |
| CVE-2020-7309 | MEDIUM | 4.8 | 0.4% | Aug 26, 2020 | Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administra... |
| CVE-2020-24656 | MEDIUM | 6.5 | 3.7% | Aug 26, 2020 | Maltego before 4.2.12 allows XXE attacks. |
| CVE-2020-19005 | MEDIUM | 5.7 | 0.7% | Aug 25, 2020 | zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can ... |
| CVE-2020-17402 | MEDIUM | 6.5 | 0.5% | Aug 25, 2020 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt... |
| CVE-2020-17401 | MEDIUM | 6 | 0.6% | Aug 25, 2020 | This vulnerability allows local attackers to disclose sensitive informations on affected installations of Parallels Desk... |
| CVE-2020-17398 | MEDIUM | 6.5 | 0.5% | Aug 25, 2020 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.4.... |
| CVE-2020-17394 | MEDIUM | 6 | 0.6% | Aug 25, 2020 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt... |
| CVE-2020-17393 | MEDIUM | 6.5 | 0.5% | Aug 25, 2020 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-... |
| CVE-2020-17391 | MEDIUM | 6.5 | 0.5% | Aug 25, 2020 | This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-... |
| CVE-2020-7824 | MEDIUM | 6.5 | 1.0% | Aug 25, 2020 | A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get admi... |
| CVE-2020-24622 | MEDIUM | 4.9 | 1.0% | Aug 25, 2020 | In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user. |
| CVE-2020-16197 | MEDIUM | 4.3 | 0.5% | Aug 25, 2020 | An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that... |
| CVE-2020-24609 | MEDIUM | 6.1 | 9.8% | Aug 25, 2020 | TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the X... |
| CVE-2020-14042 | MEDIUM | 6.1 | 1.2% | Aug 25, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and late... |
| CVE-2020-24242 | MEDIUM | 5.5 | 0.7% | Aug 25, 2020 | In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory. |
| CVE-2020-24241 | MEDIUM | 5.5 | 0.8% | Aug 25, 2020 | In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c. |
| CVE-2020-24240 | MEDIUM | 5.5 | 1.3% | Aug 25, 2020 | GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is... |
| CVE-2020-17386 | MEDIUM | 6.5 | 1.1% | Aug 25, 2020 | Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user,... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now