2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3197 | MEDIUM | 5.3 | 1.0% | Jul 16, 2020 | A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and... |
| CVE-2020-3150 | MEDIUM | 5.9 | 1.5% | Jul 16, 2020 | A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could all... |
| CVE-2020-4316 | MEDIUM | 4.7 | 1.2% | Jul 16, 2020 | IBM Publishing Engine 6.0.6, 6.0.6.1, and 7.0 does not set the secure attribute on authorization tokens or session cooki... |
| CVE-2020-15780 | MEDIUM | 6.7 | 1.3% | Jul 15, 2020 | An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI ta... |
| CVE-2020-15107 | MEDIUM | 5.3 | 0.3% | Jul 15, 2020 | In openenclave before 0.10.0, enclaves that use x87 FPU operations are vulnerable to tampering by a malicious host appli... |
| CVE-2020-9311 | MEDIUM | 5.4 | 0.6% | Jul 15, 2020 | In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile ... |
| CVE-2020-6165 | MEDIUM | 5.3 | 1.1% | Jul 15, 2020 | SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This aff... |
| CVE-2020-15051 | MEDIUM | 6.1 | 2.5% | Jul 15, 2020 | An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Add... |
| CVE-2020-14982 | MEDIUM | 6.5 | 1.3% | Jul 15, 2020 | A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352prem... |
| CVE-2020-13788 | MEDIUM | 4.3 | 1.3% | Jul 15, 2020 | Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of ... |
| CVE-2020-15718 | MEDIUM | 6.1 | 6.3% | Jul 15, 2020 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php sc... |
| CVE-2020-15366 | MEDIUM | 5.6 | 2.3% | Jul 15, 2020 | An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON sc... |
| CVE-2020-14065 | MEDIUM | 6.5 | 1.5% | Jul 15, 2020 | IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space. |
| CVE-2020-14064 | MEDIUM | 6.5 | 1.0% | Jul 15, 2020 | IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts. |
| CVE-2020-11437 | MEDIUM | 4.3 | 0.9% | Jul 15, 2020 | LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database... |
| CVE-2020-15717 | MEDIUM | 6.1 | 1.5% | Jul 15, 2020 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script... |
| CVE-2020-15716 | MEDIUM | 6.1 | 5.6% | Jul 15, 2020 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php scrip... |
| CVE-2020-2978 | MEDIUM | 4.1 | 1.2% | Jul 15, 2020 | Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that a... |
| CVE-2020-2977 | MEDIUM | 4.6 | 0.7% | Jul 15, 2020 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte... |
| CVE-2020-2976 | MEDIUM | 5.4 | 0.7% | Jul 15, 2020 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte... |
| CVE-2020-2975 | MEDIUM | 5.4 | 0.7% | Jul 15, 2020 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte... |
| CVE-2020-2974 | MEDIUM | 5.4 | 0.7% | Jul 15, 2020 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte... |
| CVE-2020-2973 | MEDIUM | 5.4 | 0.7% | Jul 15, 2020 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte... |
| CVE-2020-2972 | MEDIUM | 5.4 | 0.7% | Jul 15, 2020 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte... |
| CVE-2020-2971 | MEDIUM | 5.4 | 0.7% | Jul 15, 2020 | Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affecte... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now