2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11017 | MEDIUM | 6.5 | 1.8% | May 29, 2020 | In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condi... |
| CVE-2020-4490 | MEDIUM | 6.1 | 0.9% | May 29, 2020 | IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote atta... |
| CVE-2020-4306 | MEDIUM | 5.4 | 0.6% | May 29, 2020 | IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2020-5573 | MEDIUM | 4.6 | 0.3% | May 29, 2020 | Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in ... |
| CVE-2020-5572 | MEDIUM | 4.6 | 0.3% | May 29, 2020 | Android App 'Mailwise for Android' 1.0.0 to 1.0.1 allows an attacker to obtain credential information registered in the ... |
| CVE-2020-11082 | MEDIUM | 6.1 | 1.5% | May 28, 2020 | In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with... |
| CVE-2020-5357 | MEDIUM | 6 | 0.3% | May 28, 2020 | Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File O... |
| CVE-2020-13660 | MEDIUM | 4.8 | 0.7% | May 28, 2020 | CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name. |
| CVE-2020-13245 | MEDIUM | 5.9 | 0.5% | May 28, 2020 | Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.... |
| CVE-2020-4419 | MEDIUM | 5.4 | 0.6% | May 28, 2020 | IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2020-4249 | MEDIUM | 6.5 | 0.9% | May 28, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticat... |
| CVE-2020-4244 | MEDIUM | 5.3 | 1.1% | May 28, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information... |
| CVE-2020-4233 | MEDIUM | 5.3 | 0.8% | May 28, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, c... |
| CVE-2020-4231 | MEDIUM | 6.5 | 0.8% | May 28, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 could allow an authenticated user to perform unauthorized comman... |
| CVE-2020-11949 | MEDIUM | 6.5 | 1.2% | May 28, 2020 | testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXX... |
| CVE-2020-13645 | MEDIUM | 6.5 | 1.9% | May 28, 2020 | In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the s... |
| CVE-2020-13644 | MEDIUM | 5.4 | 0.8% | May 28, 2020 | An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax... |
| CVE-2020-8603 | MEDIUM | 6.1 | 2.0% | May 27, 2020 | A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remot... |
| CVE-2020-13633 | MEDIUM | 6.1 | 0.7% | May 27, 2020 | Fork before 5.8.3 allows XSS via navigation_title or title. |
| CVE-2020-13628 | MEDIUM | 6.1 | 2.2% | May 27, 2020 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId... |
| CVE-2020-13627 | MEDIUM | 6.1 | 2.2% | May 27, 2020 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId... |
| CVE-2020-10946 | MEDIUM | 6.1 | 2.2% | May 27, 2020 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page par... |
| CVE-2020-10945 | MEDIUM | 4.3 | 0.6% | May 27, 2020 | Centreon before 19.10.7 exposes Session IDs in server responses. |
| CVE-2020-13632 | MEDIUM | 5.5 | 0.6% | May 27, 2020 | ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. |
| CVE-2020-13631 | MEDIUM | 5.5 | 0.6% | May 27, 2020 | SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c an... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now