2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14073 | MEDIUM | 5.4 | 2.9% | Jun 23, 2020 | XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can c... |
| CVE-2020-13157 | MEDIUM | 6.5 | 0.6% | Jun 23, 2020 | modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=... |
| CVE-2020-13156 | MEDIUM | 6.5 | 0.6% | Jun 23, 2020 | modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=u... |
| CVE-2020-4188 | MEDIUM | 5.3 | 1.1% | Jun 23, 2020 | IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends o... |
| CVE-2020-9438 | MEDIUM | 5.9 | 0.7% | Jun 23, 2020 | Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred w... |
| CVE-2020-14965 | MEDIUM | 4.8 | 0.6% | Jun 23, 2020 | On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and c... |
| CVE-2020-4028 | MEDIUM | 5.3 | 0.9% | Jun 23, 2020 | Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to th... |
| CVE-2020-4033 | MEDIUM | 6.5 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with session... |
| CVE-2020-4032 | MEDIUM | 4.3 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients w... |
| CVE-2020-4030 | MEDIUM | 6.5 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks ... |
| CVE-2020-14946 | MEDIUM | 4.3 | 7.7% | Jun 22, 2020 | downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e... |
| CVE-2020-14943 | MEDIUM | 5.4 | 3.7% | Jun 22, 2020 | The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cros... |
| CVE-2020-11099 | MEDIUM | 6.5 | 2.1% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipul... |
| CVE-2020-11098 | MEDIUM | 6.5 | 1.7% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with... |
| CVE-2020-11097 | MEDIUM | 5.4 | 1.5% | Jun 22, 2020 | In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside o... |
| CVE-2020-11096 | MEDIUM | 6.5 | 1.8% | Jun 22, 2020 | In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one c... |
| CVE-2020-11095 | MEDIUM | 5.4 | 1.5% | Jun 22, 2020 | In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside o... |
| CVE-2020-1727 | MEDIUM | 5.4 | 0.8% | Jun 22, 2020 | A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks pro... |
| CVE-2020-14981 | MEDIUM | 5.9 | 0.8% | Jun 22, 2020 | The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation. |
| CVE-2020-14980 | MEDIUM | 5.9 | 1.1% | Jun 22, 2020 | The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation. |
| CVE-2020-14973 | MEDIUM | 6.1 | 1.2% | Jun 22, 2020 | The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS... |
| CVE-2020-13480 | MEDIUM | 5.4 | 1.0% | Jun 22, 2020 | Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature. |
| CVE-2020-13427 | MEDIUM | 6.1 | 0.9% | Jun 22, 2020 | Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname... |
| CVE-2020-13426 | MEDIUM | 6.5 | 1.2% | Jun 22, 2020 | The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it pre... |
| CVE-2020-9288 | MEDIUM | 5.4 | 0.9% | Jun 22, 2020 | An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now