2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12769 | MEDIUM | 5.5 | 0.7% | May 9, 2020 | An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via co... |
| CVE-2020-12768 | MEDIUM | 5.5 | 0.4% | May 9, 2020 | An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a memory leak, aka CID-... |
| CVE-2020-12767 | MEDIUM | 5.5 | 0.5% | May 9, 2020 | exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error. |
| CVE-2020-12765 | MEDIUM | 5.3 | 1.3% | May 9, 2020 | Solis Miolo 2.0 allows index.php?module=install&action=view&item= Directory Traversal. |
| CVE-2020-12764 | MEDIUM | 5.3 | 1.3% | May 9, 2020 | Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal. |
| CVE-2020-6616 | MEDIUM | 6.5 | 0.7% | May 8, 2020 | Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (P... |
| CVE-2020-11006 | MEDIUM | 5.4 | 0.6% | May 8, 2020 | In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed wh... |
| CVE-2020-12737 | MEDIUM | 6.5 | 1.1% | May 8, 2020 | An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using d... |
| CVE-2020-10690 | MEDIUM | 6.4 | 0.4% | May 8, 2020 | There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cde... |
| CVE-2020-11541 | MEDIUM | 5.5 | 0.3% | May 8, 2020 | In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local ... |
| CVE-2020-12680 | MEDIUM | 5.5 | 0.3% | May 8, 2020 | Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the execut... |
| CVE-2020-12718 | MEDIUM | 5.4 | 0.7% | May 8, 2020 | In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulne... |
| CVE-2020-11056 | MEDIUM | 6.3 | 1.0% | May 7, 2020 | In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields... |
| CVE-2020-11055 | MEDIUM | 5.4 | 0.8% | May 7, 2020 | In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A ... |
| CVE-2020-11053 | MEDIUM | 6.1 | 0.8% | May 7, 2020 | In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the prox... |
| CVE-2020-4430 | MEDIUM | 4.3 | 68.5% | May 7, 2020 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories... |
| CVE-2020-12708 | MEDIUM | 6.1 | 0.9% | May 7, 2020 | Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web scrip... |
| CVE-2020-12707 | MEDIUM | 6.1 | 1.2% | May 7, 2020 | An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only secur... |
| CVE-2020-12706 | MEDIUM | 5.4 | 2.9% | May 7, 2020 | Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web scrip... |
| CVE-2020-12705 | MEDIUM | 6.1 | 0.6% | May 7, 2020 | Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0. |
| CVE-2020-12704 | MEDIUM | 6.1 | 1.2% | May 7, 2020 | UliCMS before 2020.2 has PageController stored XSS. |
| CVE-2020-12703 | MEDIUM | 6.1 | 0.6% | May 7, 2020 | UliCMS before 2020.2 has XSS during PackageController uninstall. |
| CVE-2020-11047 | MEDIUM | 5.9 | 1.7% | May 7, 2020 | In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A ma... |
| CVE-2020-11042 | MEDIUM | 5.9 | 1.8% | May 7, 2020 | In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading... |
| CVE-2020-5751 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now