2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27280 | HIGH | 7.8 | 1.3% | Jan 26, 2021 | A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an atta... |
| CVE-2020-27098 | MEDIUM | 5.5 | 0.1% | Jan 26, 2021 | In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissi... |
| CVE-2020-27097 | MEDIUM | 5.5 | 0.1% | Jan 26, 2021 | In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to l... |
| CVE-2020-26941 | MEDIUM | 5.5 | 0.3% | Jan 26, 2021 | A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwr... |
| CVE-2020-25737 | HIGH | 7.8 | 0.3% | Jan 26, 2021 | An elevation of privilege vulnerability exists in Hackolade versions prior 4.2.0 on Windows has an issue in specific dep... |
| CVE-2020-25173 | HIGH | 7.8 | 0.3% | Jan 26, 2021 | An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reol... |
| CVE-2020-25169 | HIGH | 7.5 | 1.0% | Jan 26, 2021 | The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink serv... |
| CVE-2020-24549 | HIGH | 8.8 | 2.6% | Jan 26, 2021 | openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server. |
| CVE-2020-24085 | MEDIUM | 6.1 | 0.8% | Jan 26, 2021 | A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHo... |
| CVE-2020-23826 | HIGH | 8.8 | 12.6% | Jan 26, 2021 | The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection vi... |
| CVE-2020-23449 | HIGH | 7.5 | 0.9% | Jan 26, 2021 | newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexCon... |
| CVE-2020-23448 | CRITICAL | 9.8 | 1.6% | Jan 26, 2021 | newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginIntercep... |
| CVE-2020-23447 | MEDIUM | 6.1 | 0.7% | Jan 26, 2021 | newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their a... |
| CVE-2020-23262 | CRITICAL | 9.8 | 1.1% | Jan 26, 2021 | An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in thro... |
| CVE-2020-23162 | HIGH | 7.5 | 1.2% | Jan 26, 2021 | Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows re... |
| CVE-2020-23161 | MEDIUM | 6.5 | 2.4% | Jan 26, 2021 | Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to ... |
| CVE-2020-23160 | HIGH | 8.8 | 6.9% | Jan 26, 2021 | Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to... |
| CVE-2020-23014 | MEDIUM | 5.4 | 0.6% | Jan 26, 2021 | APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtyp... |
| CVE-2020-22643 | HIGH | 7.2 | 1.9% | Jan 26, 2021 | Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. A... |
| CVE-2020-21147 | MEDIUM | 4.8 | 0.6% | Jan 26, 2021 | RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious ... |
| CVE-2020-21146 | MEDIUM | 6.1 | 0.6% | Jan 26, 2021 | Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript ... |
| CVE-2020-20269 | CRITICAL | 9.8 | 4.7% | Jan 26, 2021 | A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.... |
| CVE-2020-17524 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-17522 | MEDIUM | 5.8 | 3.9% | Jan 26, 2021 | When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0,... |
| CVE-2020-16236 | HIGH | 7.8 | 1.2% | Jan 26, 2021 | FPWIN Pro is vulnerable to an out-of-bounds read vulnerability when a user opens a maliciously crafted project file, whi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now