2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8792 | MEDIUM | 5.3 | 1.0% | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. I... |
| CVE-2020-8791 | MEDIUM | 6.5 | 1.0% | May 4, 2020 | The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit AP... |
| CVE-2020-4209 | MEDIUM | 5.4 | 1.4% | May 4, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An ... |
| CVE-2020-12639 | MEDIUM | 6.1 | 0.7% | May 4, 2020 | phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php. |
| CVE-2020-12475 | MEDIUM | 5.5 | 0.6% | May 4, 2020 | TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.p... |
| CVE-2020-12629 | MEDIUM | 5.4 | 1.5% | May 4, 2020 | include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. |
| CVE-2020-12114 | MEDIUM | 4.7 | 0.4% | May 4, 2020 | A pivot_root race condition in fs/namespace.c in the Linux kernel 4.4.x before 4.4.221, 4.9.x before 4.9.221, 4.14.x bef... |
| CVE-2020-12626 | MEDIUM | 6.5 | 1.8% | May 4, 2020 | An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged ou... |
| CVE-2020-12625 | MEDIUM | 6.1 | 2.8% | May 4, 2020 | An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_... |
| CVE-2020-12624 | MEDIUM | 6.5 | 1.3% | May 3, 2020 | The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary... |
| CVE-2020-8157 | MEDIUM | 6.8 | 0.3% | May 2, 2020 | UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unre... |
| CVE-2020-5727 | MEDIUM | 4.6 | 0.4% | May 2, 2020 | Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated ... |
| CVE-2020-12474 | MEDIUM | 6.5 | 2.5% | May 1, 2020 | Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homo... |
| CVE-2020-12117 | MEDIUM | 5.3 | 1.4% | May 1, 2020 | Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration val... |
| CVE-2020-11037 | MEDIUM | 4.7 | 0.3% | Apr 30, 2020 | In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protec... |
| CVE-2020-11030 | MEDIUM | 5.4 | 1.4% | Apr 30, 2020 | In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the... |
| CVE-2020-11029 | MEDIUM | 6.1 | 2.1% | Apr 30, 2020 | In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited t... |
| CVE-2020-11026 | MEDIUM | 5.4 | 2.1% | Apr 30, 2020 | In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to sc... |
| CVE-2020-6867 | MEDIUM | 5.5 | 0.4% | Apr 30, 2020 | ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other... |
| CVE-2020-6866 | MEDIUM | 4.9 | 0.9% | Apr 30, 2020 | A ZTE product is impacted by a resource management error vulnerability. An attacker could exploit this vulnerability to ... |
| CVE-2020-6865 | MEDIUM | 6.5 | 0.9% | Apr 30, 2020 | ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimiz... |
| CVE-2020-5892 | MEDIUM | 6.7 | 0.3% | Apr 30, 2020 | In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attack... |
| CVE-2020-5890 | MEDIUM | 5.5 | 0.5% | Apr 30, 2020 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a Q... |
| CVE-2020-11025 | MEDIUM | 5.4 | 1.5% | Apr 30, 2020 | In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer al... |
| CVE-2020-5889 | MEDIUM | 5.4 | 0.7% | Apr 30, 2020 | On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now