2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13673 | MEDIUM | 6.1 | 0.3% | Feb 11, 2022 | The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the f... |
| CVE-2020-13672 | MEDIUM | 6.1 | 0.7% | Feb 11, 2022 | Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting... |
| CVE-2020-13669 | MEDIUM | 6.1 | 0.6% | Feb 11, 2022 | Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: D... |
| CVE-2020-13668 | MEDIUM | 6.1 | 0.7% | Feb 11, 2022 | Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected... |
| CVE-2020-12966 | MEDIUM | 5.5 | 0.3% | Feb 4, 2022 | AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypt... |
| CVE-2020-26208 | MEDIUM | 6.1 | 0.9% | Feb 2, 2022 | JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images fro... |
| CVE-2020-36056 | MEDIUM | 5.4 | 0.5% | Jan 31, 2022 | Beetel 777VR1-DI Hardware Version REV.1.01 Firmware Version V01.00.09_55 was discovered to contain a cross-site scriptin... |
| CVE-2020-19860 | MEDIUM | 6.5 | 1.3% | Jan 21, 2022 | When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vu... |
| CVE-2020-28919 | MEDIUM | 5.4 | 1.1% | Jan 15, 2022 | A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote att... |
| CVE-2020-25427 | MEDIUM | 5.5 | 0.7% | Jan 10, 2022 | A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_g... |
| CVE-2020-9061 | MEDIUM | 6.5 | 0.7% | Jan 10, 2022 | Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 vers... |
| CVE-2020-9060 | MEDIUM | 6.5 | 0.5% | Jan 10, 2022 | Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 ve... |
| CVE-2020-9059 | MEDIUM | 6.5 | 0.8% | Jan 10, 2022 | Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resourc... |
| CVE-2020-10137 | MEDIUM | 6.5 | 0.7% | Jan 10, 2022 | Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN... |
| CVE-2020-27428 | MEDIUM | 6.1 | 0.6% | Jan 6, 2022 | A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrar... |
| CVE-2020-23986 | MEDIUM | 6.1 | 0.6% | Jan 6, 2022 | Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site sc... |
| CVE-2020-15933 | MEDIUM | 5.3 | 0.8% | Jan 5, 2022 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail v... |
| CVE-2020-29292 | MEDIUM | 6.5 | 0.4% | Dec 30, 2021 | iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or ... |
| CVE-2020-20946 | MEDIUM | 5.4 | 0.6% | Dec 27, 2021 | Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&... |
| CVE-2020-20943 | MEDIUM | 4.3 | 0.4% | Dec 27, 2021 | A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force v... |
| CVE-2020-35398 | MEDIUM | 5.3 | 1.1% | Dec 23, 2021 | An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumera... |
| CVE-2020-3896 | MEDIUM | 5.5 | 0.6% | Dec 23, 2021 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.4, Security Update... |
| CVE-2020-20605 | MEDIUM | 6.1 | 0.7% | Dec 22, 2021 | Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java compone... |
| CVE-2020-20600 | MEDIUM | 5.4 | 0.7% | Dec 22, 2021 | MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=... |
| CVE-2020-20598 | MEDIUM | 6.1 | 0.8% | Dec 22, 2021 | A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitra... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now