2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11420 | MEDIUM | 6.5 | 1.6% | Apr 27, 2020 | UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exp... |
| CVE-2020-12052 | MEDIUM | 6.1 | 1.3% | Apr 27, 2020 | Grafana version < 6.7.3 is vulnerable for annotation popup XSS. |
| CVE-2020-10997 | MEDIUM | 6.5 | 1.0% | Apr 27, 2020 | Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may i... |
| CVE-2020-12270 | MEDIUM | 6.5 | 1.4% | Apr 27, 2020 | React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote... |
| CVE-2020-6213 | MEDIUM | 6.1 | 0.8% | Apr 24, 2020 | SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750,... |
| CVE-2020-6212 | MEDIUM | 5.4 | 0.7% | Apr 24, 2020 | Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (version... |
| CVE-2020-12245 | MEDIUM | 6.1 | 1.9% | Apr 24, 2020 | Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. |
| CVE-2020-11013 | MEDIUM | 5 | 1.3% | Apr 24, 2020 | Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0. `lookup` is a Helm... |
| CVE-2020-7134 | MEDIUM | 6.5 | 0.9% | Apr 24, 2020 | A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2... |
| CVE-2020-1741 | MEDIUM | 5.9 | 0.9% | Apr 24, 2020 | A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified... |
| CVE-2020-6827 | MEDIUM | 4.7 | 0.7% | Apr 24, 2020 | When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could... |
| CVE-2020-4267 | MEDIUM | 6.5 | 1.3% | Apr 24, 2020 | IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a me... |
| CVE-2020-12137 | MEDIUM | 6.1 | 2.3% | Apr 24, 2020 | GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior ma... |
| CVE-2020-12063 | MEDIUM | 5.3 | 0.9% | Apr 24, 2020 | A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homog... |
| CVE-2020-12135 | MEDIUM | 5.5 | 1.2% | Apr 24, 2020 | bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular... |
| CVE-2020-12132 | MEDIUM | 6.1 | 0.7% | Apr 24, 2020 | Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request. |
| CVE-2020-12131 | MEDIUM | 6.1 | 0.7% | Apr 24, 2020 | The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo). |
| CVE-2020-12130 | MEDIUM | 6.1 | 0.7% | Apr 24, 2020 | The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function. |
| CVE-2020-12129 | MEDIUM | 6.1 | 0.7% | Apr 24, 2020 | The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function. |
| CVE-2020-8798 | MEDIUM | 5.5 | 0.4% | Apr 23, 2020 | httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the... |
| CVE-2020-5866 | MEDIUM | 5.5 | 0.3% | Apr 23, 2020 | In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to ch... |
| CVE-2020-5865 | MEDIUM | 4.8 | 0.4% | Apr 23, 2020 | In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over une... |
| CVE-2020-8797 | MEDIUM | 6.7 | 0.9% | Apr 23, 2020 | Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call ... |
| CVE-2020-7132 | MEDIUM | 5.4 | 0.7% | Apr 23, 2020 | A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely... |
| CVE-2020-12113 | MEDIUM | 6.1 | 0.9% | Apr 23, 2020 | BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now