2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11508 | MEDIUM | 5.4 | 0.8% | Apr 7, 2020 | An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permiss... |
| CVE-2020-11611 | MEDIUM | 6.1 | 0.9% | Apr 7, 2020 | An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the ... |
| CVE-2020-9514 | MEDIUM | 6.5 | 1.0% | Apr 7, 2020 | An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in... |
| CVE-2020-11609 | MEDIUM | 4.3 | 0.6% | Apr 7, 2020 | An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06... |
| CVE-2020-11516 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minim... |
| CVE-2020-11515 | MEDIUM | 6.1 | 2.1% | Apr 7, 2020 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that red... |
| CVE-2020-11512 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subs... |
| CVE-2020-5302 | MEDIUM | 6.5 | 0.9% | Apr 7, 2020 | MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access th... |
| CVE-2020-7618 | MEDIUM | 5.3 | 1.1% | Apr 7, 2020 | sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties ... |
| CVE-2020-7616 | MEDIUM | 5.3 | 1.2% | Apr 7, 2020 | express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tri... |
| CVE-2020-11608 | MEDIUM | 4.3 | 0.5% | Apr 7, 2020 | An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferenc... |
| CVE-2020-6171 | MEDIUM | 6.1 | 4.8% | Apr 7, 2020 | A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote at... |
| CVE-2020-2176 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from ... |
| CVE-2020-2175 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI... |
| CVE-2020-2174 | MEDIUM | 6.1 | 0.8% | Apr 7, 2020 | Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation out... |
| CVE-2020-2173 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports ser... |
| CVE-2020-2172 | MEDIUM | 6.5 | 1.1% | Apr 7, 2020 | Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE... |
| CVE-2020-8096 | MEDIUM | 5.3 | 0.3% | Apr 7, 2020 | Untrusted Search Path vulnerability in Bitdefender High-Level Antimalware SDK for Windows allows an attacker to load thi... |
| CVE-2020-11591 | MEDIUM | 5.3 | 1.0% | Apr 6, 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request a... |
| CVE-2020-11590 | MEDIUM | 5.3 | 1.0% | Apr 6, 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET requ... |
| CVE-2020-11588 | MEDIUM | 5.3 | 1.0% | Apr 6, 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET requ... |
| CVE-2020-11585 | MEDIUM | 4.3 | 0.7% | Apr 6, 2020 | There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Us... |
| CVE-2020-5300 | MEDIUM | 5.3 | 1.0% | Apr 6, 2020 | In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, ... |
| CVE-2020-11102 | MEDIUM | 5.6 | 1.9% | Apr 6, 2020 | hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not val... |
| CVE-2020-9473 | MEDIUM | 6.6 | 1.0% | Apr 6, 2020 | The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now