2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11883 | MEDIUM | 5.3 | 15.2% | Apr 17, 2020 | In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpect... |
| CVE-2020-0077 | MEDIUM | 4.4 | 0.1% | Apr 17, 2020 | In authorize_enroll of the FPC IRIS TrustZone app, there is a possible out of bounds read due to a missing bounds check.... |
| CVE-2020-0076 | MEDIUM | 6.7 | 0.2% | Apr 17, 2020 | In get_auth_result of the FPC IRIS TrustZone app, there is a possible out of bounds write due to a missing bounds check.... |
| CVE-2020-0075 | MEDIUM | 4.4 | 0.1% | Apr 17, 2020 | In set_shared_key of the FPC IRIS TrustZone app, there is a possible out of bounds read due to a missing bounds check. T... |
| CVE-2020-0068 | MEDIUM | 4.4 | 0.1% | Apr 17, 2020 | In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This ... |
| CVE-2020-0067 | MEDIUM | 4.4 | 0.5% | Apr 17, 2020 | In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could ... |
| CVE-2020-7084 | MEDIUM | 5.5 | 0.8% | Apr 17, 2020 | A NULL pointer dereference vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of servi... |
| CVE-2020-7083 | MEDIUM | 6.5 | 1.0% | Apr 17, 2020 | An intager overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of t... |
| CVE-2020-11880 | MEDIUM | 6.5 | 0.9% | Apr 17, 2020 | An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." paramete... |
| CVE-2020-11879 | MEDIUM | 6.5 | 2.7% | Apr 17, 2020 | An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." pa... |
| CVE-2020-5294 | MEDIUM | 5.4 | 0.7% | Apr 16, 2020 | PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is ... |
| CVE-2020-5273 | MEDIUM | 5.4 | 0.7% | Apr 16, 2020 | In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fix... |
| CVE-2020-5266 | MEDIUM | 5.4 | 0.6% | Apr 16, 2020 | In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list blo... |
| CVE-2020-7113 | MEDIUM | 4.9 | 0.9% | Apr 16, 2020 | A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to inte... |
| CVE-2020-7110 | MEDIUM | 4.8 | 0.6% | Apr 16, 2020 | ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administr... |
| CVE-2020-2177 | MEDIUM | 4.3 | 0.5% | Apr 16, 2020 | Jenkins Copr Plugin 0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where t... |
| CVE-2020-11823 | MEDIUM | 5.4 | 0.7% | Apr 16, 2020 | In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit pag... |
| CVE-2020-11814 | MEDIUM | 5.4 | 1.0% | Apr 16, 2020 | A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users ... |
| CVE-2020-11813 | MEDIUM | 5.4 | 0.5% | Apr 16, 2020 | In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the configuration page via the copyright text input. Thus, ... |
| CVE-2020-11007 | MEDIUM | 6.5 | 0.9% | Apr 16, 2020 | In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated ... |
| CVE-2020-4338 | MEDIUM | 5.5 | 0.3% | Apr 16, 2020 | IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras... |
| CVE-2020-4260 | MEDIUM | 4.3 | 0.9% | Apr 16, 2020 | IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic... |
| CVE-2020-5721 | MEDIUM | 5.5 | 0.4% | Apr 15, 2020 | MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the ... |
| CVE-2020-3261 | MEDIUM | 6.5 | 0.5% | Apr 15, 2020 | A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated,... |
| CVE-2020-3260 | MEDIUM | 6.5 | 0.5% | Apr 15, 2020 | A vulnerability in Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to caus... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now