2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35704 | MEDIUM | 5.4 | 0.6% | Dec 25, 2020 | Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen. |
| CVE-2020-35702 | HIGH | 7.8 | 0.9% | Dec 25, 2020 | DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE... |
| CVE-2020-26282 | CRITICAL | 10 | 4.6% | Dec 24, 2020 | BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data ... |
| CVE-2020-29474 | CRITICAL | 9.8 | 4.1% | Dec 24, 2020 | EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access usin... |
| CVE-2020-29472 | CRITICAL | 9.8 | 4.1% | Dec 24, 2020 | EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admi... |
| CVE-2020-29247 | MEDIUM | 4.8 | 1.1% | Dec 24, 2020 | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in ... |
| CVE-2020-28912 | HIGH | 7 | 0.4% | Dec 24, 2020 | With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivi... |
| CVE-2020-11093 | HIGH | 7.5 | 0.9% | Dec 24, 2020 | Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperle... |
| CVE-2020-35693 | HIGH | 8.8 | 0.4% | Dec 24, 2020 | On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Lo... |
| CVE-2020-24658 | HIGH | 7.8 | 0.3% | Dec 24, 2020 | Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overfl... |
| CVE-2020-9202 | MEDIUM | 4.4 | 0.2% | Dec 24, 2020 | There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to th... |
| CVE-2020-9201 | MEDIUM | 6.5 | 0.3% | Dec 24, 2020 | There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software re... |
| CVE-2020-9200 | HIGH | 7.8 | 0.3% | Dec 24, 2020 | There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege ... |
| CVE-2020-9137 | MEDIUM | 6.7 | 0.2% | Dec 24, 2020 | There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 an... |
| CVE-2020-9120 | HIGH | 7.5 | 0.7% | Dec 24, 2020 | CloudEngine 1800V versions V100R019C10SPC500 has a resource management error vulnerability. Remote unauthorized attacker... |
| CVE-2020-9119 | MEDIUM | 6.2 | 0.2% | Dec 24, 2020 | There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to p... |
| CVE-2020-35680 | HIGH | 7.5 | 3.6% | Dec 24, 2020 | smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of ... |
| CVE-2020-35679 | HIGH | 7.5 | 2.8% | Dec 24, 2020 | smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very signif... |
| CVE-2020-35659 | MEDIUM | 6.1 | 0.9% | Dec 24, 2020 | The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indir... |
| CVE-2020-27729 | MEDIUM | 6.1 | 0.6% | Dec 24, 2020 | In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an u... |
| CVE-2020-27728 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | On BIG-IP ASM & Advanced WAF versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, under certain conditions, Ana... |
| CVE-2020-27727 | MEDIUM | 4.9 | 0.8% | Dec 24, 2020 | On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administra... |
| CVE-2020-27726 | MEDIUM | 6.1 | 0.6% | Dec 24, 2020 | In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-sit... |
| CVE-2020-27723 | HIGH | 7.5 | 1.0% | Dec 24, 2020 | In versions 14.1.0-14.1.3 and 13.1.0-13.1.3.4, a BIG-IP APM virtual server processing PingAccess requests may lead to a ... |
| CVE-2020-27722 | MEDIUM | 6.5 | 0.9% | Dec 24, 2020 | In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin doe... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now