2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15307 | MEDIUM | 6.1 | 0.7% | Jun 30, 2020 | Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to... |
| CVE-2020-15085 | MEDIUM | 6.1 | 0.6% | Jun 30, 2020 | In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the ... |
| CVE-2020-15412 | MEDIUM | 4.3 | 0.7% | Jun 30, 2020 | An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding ... |
| CVE-2020-15401 | MEDIUM | 4.4 | 0.4% | Jun 30, 2020 | IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious fl... |
| CVE-2020-15400 | MEDIUM | 4.3 | 0.4% | Jun 30, 2020 | CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS. |
| CVE-2020-5588 | MEDIUM | 4.9 | 1.0% | Jun 30, 2020 | Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain uninten... |
| CVE-2020-5587 | MEDIUM | 6.5 | 1.1% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vecto... |
| CVE-2020-5586 | MEDIUM | 4.8 | 0.5% | Jun 30, 2020 | Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject ... |
| CVE-2020-5585 | MEDIUM | 4.8 | 0.5% | Jun 30, 2020 | Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to inject a... |
| CVE-2020-5583 | MEDIUM | 6.5 | 1.0% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to obtain unauthorized M... |
| CVE-2020-5582 | MEDIUM | 4.3 | 0.8% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for th... |
| CVE-2020-5581 | MEDIUM | 6.5 | 1.8% | Jun 30, 2020 | Path traversal vulnerability in Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to obtain unintended ... |
| CVE-2020-15393 | MEDIUM | 5.5 | 0.4% | Jun 29, 2020 | In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebe... |
| CVE-2020-15389 | MEDIUM | 6.5 | 2.6% | Jun 29, 2020 | jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and... |
| CVE-2020-15368 | MEDIUM | 5.5 | 1.3% | Jun 29, 2020 | AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering ... |
| CVE-2020-4037 | MEDIUM | 5.4 | 0.9% | Jun 29, 2020 | In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to se... |
| CVE-2020-15043 | MEDIUM | 6.5 | 0.4% | Jun 29, 2020 | iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the... |
| CVE-2020-14145 | MEDIUM | 5.9 | 2.1% | Jun 29, 2020 | The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm... |
| CVE-2020-14002 | MEDIUM | 5.9 | 3.1% | Jun 29, 2020 | PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This ... |
| CVE-2020-13896 | MEDIUM | 5.3 | 14.8% | Jun 29, 2020 | The web interface of Maipu MP1800X-50 7.5.3.14(R) devices allows remote attackers to obtain sensitive information via th... |
| CVE-2020-13657 | MEDIUM | 5.5 | 0.4% | Jun 29, 2020 | An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to imprope... |
| CVE-2020-14413 | MEDIUM | 6.1 | 3.4% | Jun 29, 2020 | NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function at... |
| CVE-2020-14071 | MEDIUM | 6.1 | 0.7% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. XSS vulnerabilities in admin and client scripts allow an attacker to execute a... |
| CVE-2020-14069 | MEDIUM | 6.8 | 0.4% | Jun 29, 2020 | An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php... |
| CVE-2020-15319 | MEDIUM | 5.9 | 1.0% | Jun 29, 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now