2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3884 | MEDIUM | 6.1 | 1.1% | Apr 1, 2020 | An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attac... |
| CVE-2020-3881 | MEDIUM | 5.5 | 0.3% | Apr 1, 2020 | A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user ... |
| CVE-2020-10864 | MEDIUM | 6.5 | 1.6% | Apr 1, 2020 | An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi... |
| CVE-2020-11457 | MEDIUM | 5.4 | 9.3% | Apr 1, 2020 | pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n... |
| CVE-2020-11456 | MEDIUM | 5.4 | 70.8% | Apr 1, 2020 | LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and applicati... |
| CVE-2020-6753 | MEDIUM | 6.1 | 1.3% | Apr 1, 2020 | The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-202... |
| CVE-2020-5392 | MEDIUM | 6.1 | 1.3% | Apr 1, 2020 | A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings... |
| CVE-2020-7263 | MEDIUM | 6.7 | 0.2% | Apr 1, 2020 | Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current vers... |
| CVE-2020-7066 | MEDIUM | 4.3 | 2.8% | Apr 1, 2020 | In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-suppli... |
| CVE-2020-7064 | MEDIUM | 5.4 | 4.3% | Apr 1, 2020 | In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data... |
| CVE-2020-11445 | MEDIUM | 5.3 | 1.8% | Apr 1, 2020 | TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive informatio... |
| CVE-2020-11441 | MEDIUM | 6.1 | 2.3% | Mar 31, 2020 | phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF s... |
| CVE-2020-4240 | MEDIUM | 6.5 | 1.9% | Mar 31, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An ... |
| CVE-2020-4239 | MEDIUM | 5.3 | 1.7% | Mar 31, 2020 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a ... |
| CVE-2020-4236 | MEDIUM | 6.5 | 1.4% | Mar 31, 2020 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to... |
| CVE-2020-4235 | MEDIUM | 5.4 | 0.7% | Mar 31, 2020 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2020-9055 | MEDIUM | 5.4 | 0.5% | Mar 30, 2020 | Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could al... |
| CVE-2020-5289 | MEDIUM | 6.5 | 1.3% | Mar 30, 2020 | In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have... |
| CVE-2020-5284 | MEDIUM | 4.3 | 43.4% | Mar 30, 2020 | Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access... |
| CVE-2020-11106 | MEDIUM | 6.1 | 0.9% | Mar 30, 2020 | An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION... |
| CVE-2020-11104 | MEDIUM | 5.3 | 1.5% | Mar 30, 2020 | An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable i... |
| CVE-2020-5725 | MEDIUM | 5.9 | 1.7% | Mar 30, 2020 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo... |
| CVE-2020-5274 | MEDIUM | 5.4 | 1.2% | Mar 30, 2020 | In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHa... |
| CVE-2020-5255 | MEDIUM | 4.3 | 1.3% | Mar 30, 2020 | In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected version... |
| CVE-2020-7599 | MEDIUM | 6.5 | 0.5% | Mar 30, 2020 | All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log Fi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now