2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11925 | HIGH | 8.8 | 1.3% | Apr 2, 2021 | An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a u... |
| CVE-2020-11922 | MEDIUM | 4.3 | 1.1% | Apr 2, 2021 | An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller serve... |
| CVE-2020-19619 | MEDIUM | 5.4 | 0.6% | Apr 1, 2021 | Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. |
| CVE-2020-19618 | MEDIUM | 5.4 | 0.6% | Apr 1, 2021 | Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. |
| CVE-2020-19617 | MEDIUM | 5.4 | 0.6% | Apr 1, 2021 | Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile. |
| CVE-2020-19616 | MEDIUM | 5.4 | 0.6% | Apr 1, 2021 | Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. |
| CVE-2020-19613 | HIGH | 7.5 | 1.3% | Apr 1, 2021 | Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version... |
| CVE-2020-9149 | MEDIUM | 5.5 | 0.2% | Apr 1, 2021 | An application error verification vulnerability exists in a component interface of Huawei Smartphone. Local attackers ca... |
| CVE-2020-9148 | MEDIUM | 5.5 | 0.2% | Apr 1, 2021 | An application bypass mechanism vulnerability exists in a component interface of Huawei Smartphone. Local attackers can ... |
| CVE-2020-9147 | HIGH | 7.8 | 0.2% | Apr 1, 2021 | A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit th... |
| CVE-2020-9146 | MEDIUM | 5.5 | 0.1% | Apr 1, 2021 | A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit th... |
| CVE-2020-36286 | MEDIUM | 5.3 | 1.4% | Apr 1, 2021 | The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before versio... |
| CVE-2020-36238 | MEDIUM | 5.3 | 1.6% | Apr 1, 2021 | The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before versio... |
| CVE-2020-24550 | MEDIUM | 6.1 | 4.7% | Mar 31, 2021 | An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted website... |
| CVE-2020-35308 | CRITICAL | 9.8 | 1.5% | Mar 31, 2021 | CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute mal... |
| CVE-2020-28173 | HIGH | 7.2 | 3.2% | Mar 31, 2021 | Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_setting... |
| CVE-2020-28172 | CRITICAL | 9.8 | 3.0% | Mar 31, 2021 | A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin ... |
| CVE-2020-24995 | HIGH | 7.8 | 0.6% | Mar 30, 2021 | Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to ... |
| CVE-2020-24391 | CRITICAL | 9.8 | 75.1% | Mar 30, 2021 | mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this m... |
| CVE-2020-4944 | MEDIUM | 5.5 | 0.2% | Mar 30, 2021 | IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore p... |
| CVE-2020-4884 | MEDIUM | 5.5 | 0.2% | Mar 30, 2021 | IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be rea... |
| CVE-2020-4848 | MEDIUM | 5.4 | 0.6% | Mar 30, 2021 | IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compa... |
| CVE-2020-15075 | HIGH | 7.1 | 0.3% | Mar 30, 2021 | OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access ... |
| CVE-2020-20545 | MEDIUM | 5.4 | 0.6% | Mar 30, 2021 | Cross-Site Scripting (XSS) vulnerability in Zhiyuan G6 Government Collaboration System V6.1SP1, via the 'method' paramet... |
| CVE-2020-19643 | MEDIUM | 6.1 | 0.7% | Mar 30, 2021 | Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now