2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10722 | MEDIUM | 6.7 | 0.4% | May 19, 2020 | A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_lo... |
| CVE-2020-10135 | MEDIUM | 5.4 | 2.4% | May 19, 2020 | Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may... |
| CVE-2020-10134 | MEDIUM | 6.3 | 0.7% | May 19, 2020 | Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairi... |
| CVE-2020-8021 | MEDIUM | 5.3 | 1.3% | May 19, 2020 | a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package... |
| CVE-2020-11845 | MEDIUM | 6.1 | 0.8% | May 19, 2020 | Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.... |
| CVE-2020-8617 | MEDIUM | 5.9 | 93.4% | May 19, 2020 | Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the... |
| CVE-2020-6956 | MEDIUM | 6.1 | 0.7% | May 19, 2020 | PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp. |
| CVE-2020-4412 | MEDIUM | 5.3 | 1.3% | May 19, 2020 | The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of... |
| CVE-2020-4298 | MEDIUM | 5.4 | 0.6% | May 19, 2020 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2020-4286 | MEDIUM | 6.5 | 0.5% | May 19, 2020 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an ... |
| CVE-2020-13154 | MEDIUM | 6.5 | 3.1% | May 18, 2020 | Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Pro... |
| CVE-2020-13153 | MEDIUM | 6.1 | 0.8% | May 18, 2020 | app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. |
| CVE-2020-13094 | MEDIUM | 5.4 | 1.1% | May 18, 2020 | Dolibarr before 11.0.4 allows XSS. |
| CVE-2020-13145 | MEDIUM | 5.4 | 0.5% | May 18, 2020 | Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can ... |
| CVE-2020-13143 | MEDIUM | 6.5 | 5.2% | May 18, 2020 | gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup wit... |
| CVE-2020-8034 | MEDIUM | 6.1 | 1.0% | May 18, 2020 | Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected C... |
| CVE-2020-6093 | MEDIUM | 5.5 | 2.6% | May 18, 2020 | An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A sp... |
| CVE-2020-13135 | MEDIUM | 6.5 | 0.8% | May 18, 2020 | D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstra... |
| CVE-2020-11550 | MEDIUM | 6.5 | 1.6% | May 18, 2020 | An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel... |
| CVE-2020-8035 | MEDIUM | 6.1 | 0.9% | May 18, 2020 | The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripti... |
| CVE-2020-12801 | MEDIUM | 5.3 | 1.3% | May 18, 2020 | If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffic... |
| CVE-2020-12256 | MEDIUM | 5.4 | 92.8% | May 18, 2020 | rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can ... |
| CVE-2020-10967 | MEDIUM | 5.3 | 8.2% | May 18, 2020 | In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail wi... |
| CVE-2020-9524 | MEDIUM | 5.4 | 0.5% | May 18, 2020 | Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions pri... |
| CVE-2020-10958 | MEDIUM | 5.3 | 6.1% | May 18, 2020 | In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-log... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now