2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5750 | MEDIUM | 6.1 | 1.1% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-... |
| CVE-2020-5749 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si... |
| CVE-2020-5748 | MEDIUM | 6.1 | 1.1% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-... |
| CVE-2020-5747 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si... |
| CVE-2020-5746 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-si... |
| CVE-2020-5744 | MEDIUM | 4.9 | 1.4% | May 7, 2020 | Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files... |
| CVE-2020-5743 | MEDIUM | 4.3 | 0.8% | May 7, 2020 | Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadat... |
| CVE-2020-12679 | MEDIUM | 6.1 | 0.8% | May 7, 2020 | A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 befor... |
| CVE-2020-12448 | MEDIUM | 5.3 | 1.2% | May 7, 2020 | GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet. |
| CVE-2020-12687 | MEDIUM | 6.5 | 1.0% | May 7, 2020 | An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin aut... |
| CVE-2020-12683 | MEDIUM | 5.4 | 0.6% | May 7, 2020 | Katyshop2 before 2.12 has multiple stored XSS issues. |
| CVE-2020-12696 | MEDIUM | 6.1 | 2.0% | May 7, 2020 | The iframe plugin before 4.5 for WordPress does not sanitize a URL. |
| CVE-2020-12692 | MEDIUM | 5.4 | 0.7% | May 7, 2020 | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check ... |
| CVE-2020-11727 | MEDIUM | 6.1 | 2.0% | May 6, 2020 | A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordP... |
| CVE-2020-3329 | MEDIUM | 4.3 | 0.7% | May 6, 2020 | A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Direc... |
| CVE-2020-3315 | MEDIUM | 5.3 | 2.2% | May 6, 2020 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticate... |
| CVE-2020-3313 | MEDIUM | 6.1 | 0.8% | May 6, 2020 | A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote... |
| CVE-2020-3311 | MEDIUM | 6.1 | 0.8% | May 6, 2020 | A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated,... |
| CVE-2020-3310 | MEDIUM | 4.9 | 1.2% | May 6, 2020 | A vulnerability in the XML parser code of Cisco Firepower Device Manager On-Box software could allow an authenticated, r... |
| CVE-2020-3308 | MEDIUM | 4.9 | 0.6% | May 6, 2020 | A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow... |
| CVE-2020-3307 | MEDIUM | 5.3 | 1.0% | May 6, 2020 | A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote... |
| CVE-2020-3301 | MEDIUM | 4.4 | 0.8% | May 6, 2020 | Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software cou... |
| CVE-2020-3285 | MEDIUM | 5.8 | 1.4% | May 6, 2020 | A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco F... |
| CVE-2020-3256 | MEDIUM | 4.9 | 1.2% | May 6, 2020 | A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Softwa... |
| CVE-2020-3253 | MEDIUM | 6.7 | 0.3% | May 6, 2020 | A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authentica... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now