2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15064MEDIUM4.3DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct per...
CVE-2020-15061MEDIUM6.5Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-s...
CVE-2020-15060MEDIUM4.3Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct per...
CVE-2020-15057MEDIUM6.5TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to denial-of-s...
CVE-2020-15056MEDIUM4.3TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to conduct per...
CVE-2020-5412MEDIUM6.5Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow...
CVE-2020-15907MEDIUM6.1In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or fol...
CVE-2020-11985MEDIUM5.3IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip...
CVE-2020-16168MEDIUM6.5Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access...
CVE-2020-15701MEDIUM5.5An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of ...
CVE-2020-15136MEDIUM6.5In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV r...
CVE-2020-11937MEDIUM5.5In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The...
CVE-2020-16211MEDIUM5.5Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by p...
CVE-2020-7459MEDIUM6.8In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 1...
CVE-2020-9036MEDIUM6.1Jeedom through 4.0.38 allows XSS.
CVE-2020-15132MEDIUM5.3In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu ...
CVE-2020-16254MEDIUM6.1The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
CVE-2020-15112MEDIUM6.5In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in t...
CVE-2020-15106MEDIUM6.5In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is st...
CVE-2020-16192MEDIUM6.1LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parame...
CVE-2020-17364MEDIUM6.1USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
CVE-2020-8607MEDIUM6.7An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific ro...
CVE-2020-16252MEDIUM4.3The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.
CVE-2020-14347MEDIUM5.5A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X...
CVE-2020-14344MEDIUM6.7An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in li...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now