2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12259 | MEDIUM | 5.4 | 94.8% | May 18, 2020 | rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can... |
| CVE-2020-12860 | MEDIUM | 5.3 | 1.0% | May 18, 2020 | COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can h... |
| CVE-2020-12859 | MEDIUM | 5.3 | 0.7% | May 18, 2020 | Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify ... |
| CVE-2020-13125 | MEDIUM | 6.5 | 2.3% | May 17, 2020 | An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the w... |
| CVE-2020-13121 | MEDIUM | 6.1 | 3.5% | May 16, 2020 | Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt. |
| CVE-2020-1758 | MEDIUM | 5.9 | 0.9% | May 15, 2020 | A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while se... |
| CVE-2020-13093 | MEDIUM | 5.3 | 1.3% | May 15, 2020 | iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal. |
| CVE-2020-12872 | MEDIUM | 5.5 | 0.4% | May 15, 2020 | yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet3... |
| CVE-2020-12888 | MEDIUM | 5.3 | 0.4% | May 15, 2020 | The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. |
| CVE-2020-12685 | MEDIUM | 6.1 | 0.8% | May 15, 2020 | XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote... |
| CVE-2020-11524 | MEDIUM | 6.6 | 1.8% | May 15, 2020 | libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. |
| CVE-2020-11523 | MEDIUM | 6.6 | 2.0% | May 15, 2020 | libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow. |
| CVE-2020-11522 | MEDIUM | 6.5 | 2.7% | May 15, 2020 | libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read. |
| CVE-2020-11521 | MEDIUM | 6.6 | 1.9% | May 15, 2020 | libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. |
| CVE-2020-7809 | MEDIUM | 6.1 | 0.6% | May 15, 2020 | ALSong 3.46 and earlier version contain a Document Object Model (DOM) based cross-site scripting vulnerability caused by... |
| CVE-2020-3810 | MEDIUM | 5.5 | 1.3% | May 15, 2020 | Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service whe... |
| CVE-2020-10744 | MEDIUM | 5 | 0.3% | May 15, 2020 | An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running bec... |
| CVE-2020-12882 | MEDIUM | 5.4 | 1.2% | May 15, 2020 | Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a ... |
| CVE-2020-12068 | MEDIUM | 6.5 | 0.9% | May 14, 2020 | An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are... |
| CVE-2020-12046 | MEDIUM | 5.7 | 0.5% | May 14, 2020 | Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware updat... |
| CVE-2020-12042 | MEDIUM | 6.5 | 0.5% | May 14, 2020 | Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware ... |
| CVE-2020-0220 | MEDIUM | 6.7 | 0.1% | May 14, 2020 | In crus_afe_callback of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. Th... |
| CVE-2020-0106 | MEDIUM | 5.5 | 0.1% | May 14, 2020 | In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version che... |
| CVE-2020-0104 | MEDIUM | 5.5 | 0.2% | May 14, 2020 | In onShowingStateChanged of KeyguardStateMonitor.java, there is a possible inappropriate read due to a logic error. This... |
| CVE-2020-0101 | MEDIUM | 5.5 | 0.1% | May 14, 2020 | In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now