2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-8792MEDIUM5.3The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. I...
CVE-2020-8791MEDIUM6.5The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit AP...
CVE-2020-4209MEDIUM5.4IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An ...
CVE-2020-12639MEDIUM6.1phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
CVE-2020-12475MEDIUM5.5TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.p...
CVE-2020-12629MEDIUM5.4include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
CVE-2020-12114MEDIUM4.7A pivot_root race condition in fs/namespace.c in the Linux kernel 4.4.x before 4.4.221, 4.9.x before 4.9.221, 4.14.x bef...
CVE-2020-12626MEDIUM6.5An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged ou...
CVE-2020-12625MEDIUM6.1An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_...
CVE-2020-12624MEDIUM6.5The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary...
CVE-2020-8157MEDIUM6.8UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unre...
CVE-2020-5727MEDIUM4.6Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated ...
CVE-2020-12474MEDIUM6.5Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homo...
CVE-2020-12117MEDIUM5.3Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration val...
CVE-2020-11037MEDIUM4.7In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protec...
CVE-2020-11030MEDIUM5.4In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the...
CVE-2020-11029MEDIUM6.1In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited t...
CVE-2020-11026MEDIUM5.4In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to sc...
CVE-2020-6867MEDIUM5.5ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other...
CVE-2020-6866MEDIUM4.9A ZTE product is impacted by a resource management error vulnerability. An attacker could exploit this vulnerability to ...
CVE-2020-6865MEDIUM6.5ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimiz...
CVE-2020-5892MEDIUM6.7In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attack...
CVE-2020-5890MEDIUM5.5On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a Q...
CVE-2020-11025MEDIUM5.4In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer al...
CVE-2020-5889MEDIUM5.4On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now