2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6872 | MEDIUM | 6.1 | 0.7% | Jul 20, 2020 | The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes thr... |
| CVE-2020-15118 | MEDIUM | 5.4 | 1.1% | Jul 20, 2020 | In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagt... |
| CVE-2020-15111 | MEDIUM | 5.4 | 0.9% | Jul 20, 2020 | In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is... |
| CVE-2020-15053 | MEDIUM | 6.1 | 1.8% | Jul 20, 2020 | An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time ... |
| CVE-2020-7680 | MEDIUM | 6.1 | 4.5% | Jul 20, 2020 | docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a... |
| CVE-2020-12027 | MEDIUM | 4.3 | 53.0% | Jul 20, 2020 | All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote,... |
| CVE-2020-14491 | MEDIUM | 6.5 | 0.8% | Jul 20, 2020 | OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may al... |
| CVE-2020-4527 | MEDIUM | 5.9 | 1.3% | Jul 20, 2020 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t... |
| CVE-2020-4466 | MEDIUM | 6.5 | 1.4% | Jul 20, 2020 | IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attacker could cause a denial of service due t... |
| CVE-2020-4361 | MEDIUM | 4.3 | 1.0% | Jul 20, 2020 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addres... |
| CVE-2020-9256 | MEDIUM | 6.5 | 0.6% | Jul 18, 2020 | Huawei Mate 30 Pro smartphones with versions earlier than 10.1.0.150(C00E136R5P3) have an improper authorization vulnera... |
| CVE-2020-9101 | MEDIUM | 6.5 | 0.3% | Jul 18, 2020 | There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets wit... |
| CVE-2020-9259 | MEDIUM | 6.5 | 0.8% | Jul 17, 2020 | Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerab... |
| CVE-2020-9255 | MEDIUM | 5.5 | 0.5% | Jul 17, 2020 | Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability. C... |
| CVE-2020-9227 | MEDIUM | 5.5 | 0.5% | Jul 17, 2020 | Huawei Smart Phones Moana-AL00B with versions earlier than 10.1.0.166 have a missing initialization of resource vulnerab... |
| CVE-2020-5769 | MEDIUM | 5.4 | 0.6% | Jul 17, 2020 | Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduc... |
| CVE-2020-5768 | MEDIUM | 4.9 | 2.0% | Jul 17, 2020 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & News... |
| CVE-2020-5767 | MEDIUM | 6.5 | 0.9% | Jul 17, 2020 | Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attack... |
| CVE-2020-4104 | MEDIUM | 5.4 | 0.5% | Jul 17, 2020 | HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can us... |
| CVE-2020-0122 | MEDIUM | 6.7 | 0.2% | Jul 17, 2020 | In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, th... |
| CVE-2020-0107 | MEDIUM | 5.5 | 0.1% | Jul 17, 2020 | In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validati... |
| CVE-2020-0305 | MEDIUM | 6.4 | 0.2% | Jul 17, 2020 | In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalati... |
| CVE-2020-1655 | MEDIUM | 5.3 | 1.0% | Jul 17, 2020 | When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configur... |
| CVE-2020-1651 | MEDIUM | 6.5 | 0.5% | Jul 17, 2020 | On Juniper Networks MX series, receipt of a stream of specific Layer 2 frames may cause a memory leak resulting in the p... |
| CVE-2020-1643 | MEDIUM | 5.5 | 0.3% | Jul 17, 2020 | Execution of the "show ospf interface extensive" or "show ospf interface detail" CLI commands on a Juniper Networks devi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now