2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28483 | HIGH | 7.1 | 1.3% | Jan 20, 2021 | This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's ... |
| CVE-2020-28452 | HIGH | 8.8 | 0.5% | Jan 20, 2021 | This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package c... |
| CVE-2020-25687 | MEDIUM | 5.9 | 86.8% | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is e... |
| CVE-2020-25686 | LOW | 3.7 | 4.9% | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending ... |
| CVE-2020-25682 | HIGH | 8.1 | 71.0% | Jan 20, 2021 | A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names... |
| CVE-2020-25681 | HIGH | 8.1 | 81.3% | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorte... |
| CVE-2020-35272 | MEDIUM | 4.8 | 0.6% | Jan 20, 2021 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in t... |
| CVE-2020-35271 | MEDIUM | 4.8 | 0.5% | Jan 20, 2021 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in t... |
| CVE-2020-25685 | LOW | 3.7 | 2.2% | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.... |
| CVE-2020-25684 | LOW | 3.7 | 4.1% | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forw... |
| CVE-2020-25683 | MEDIUM | 5.9 | 86.2% | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is e... |
| CVE-2020-20949 | MEDIUM | 5.9 | 0.9% | Jan 20, 2021 | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for S... |
| CVE-2020-14360 | HIGH | 7.8 | 0.4% | Jan 20, 2021 | A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead ... |
| CVE-2020-4983 | HIGH | 7.8 | 0.4% | Jan 20, 2021 | IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to subm... |
| CVE-2020-4921 | HIGH | 8.8 | 1.5% | Jan 20, 2021 | IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL s... |
| CVE-2020-4887 | MEDIUM | 5.5 | 0.3% | Jan 20, 2021 | IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to cre... |
| CVE-2020-4688 | HIGH | 7.8 | 0.9% | Jan 20, 2021 | IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unpri... |
| CVE-2020-14756 | CRITICAL | 9.8 | 74.8% | Jan 20, 2021 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versio... |
| CVE-2020-35217 | HIGH | 8.8 | 0.6% | Jan 20, 2021 | Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF toke... |
| CVE-2020-27852 | MEDIUM | 5.4 | 0.6% | Jan 20, 2021 | A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allo... |
| CVE-2020-27851 | MEDIUM | 5.4 | 0.6% | Jan 20, 2021 | Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketg... |
| CVE-2020-27850 | MEDIUM | 4.8 | 0.6% | Jan 20, 2021 | A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 al... |
| CVE-2020-13134 | MEDIUM | 4.8 | 0.5% | Jan 20, 2021 | Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires a... |
| CVE-2020-13133 | MEDIUM | 6.1 | 0.7% | Jan 20, 2021 | Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires a... |
| CVE-2020-25385 | MEDIUM | 6.1 | 16.2% | Jan 20, 2021 | Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapsho... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now