2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35624 | MEDIUM | 5.3 | 1.0% | Dec 21, 2020 | An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a ful... |
| CVE-2020-35623 | HIGH | 7.5 | 1.1% | Dec 21, 2020 | An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it a... |
| CVE-2020-35622 | MEDIUM | 6.1 | 0.7% | Dec 21, 2020 | An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap:... |
| CVE-2020-26284 | HIGH | 8.5 | 1.5% | Dec 21, 2020 | Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g.... |
| CVE-2020-8995 | CRITICAL | 9.8 | 2.1% | Dec 21, 2020 | Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to differ... |
| CVE-2020-29596 | HIGH | 7.5 | 2.7% | Dec 21, 2020 | MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the f... |
| CVE-2020-26281 | HIGH | 7.5 | 1.0% | Dec 21, 2020 | async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1... |
| CVE-2020-26277 | MEDIUM | 6.1 | 1.2% | Dec 21, 2020 | DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a ... |
| CVE-2020-35151 | HIGH | 8.8 | 3.8% | Dec 21, 2020 | The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to ... |
| CVE-2020-11717 | CRITICAL | 9.8 | 2.0% | Dec 21, 2020 | An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities. |
| CVE-2020-35606 | HIGH | 8.8 | 28.0% | Dec 21, 2020 | Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex... |
| CVE-2020-35605 | CRITICAL | 9.8 | 3.6% | Dec 21, 2020 | The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code bec... |
| CVE-2020-35604 | CRITICAL | 9.8 | 1.6% | Dec 21, 2020 | An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used. |
| CVE-2020-21378 | CRITICAL | 9.8 | 2.1% | Dec 21, 2020 | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.ph... |
| CVE-2020-21377 | CRITICAL | 9.8 | 1.0% | Dec 21, 2020 | SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter. |
| CVE-2020-6882 | HIGH | 7.5 | 1.2% | Dec 21, 2020 | ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service ... |
| CVE-2020-6881 | HIGH | 7.5 | 0.6% | Dec 21, 2020 | ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to ver... |
| CVE-2020-5808 | HIGH | 7.5 | 1.1% | Dec 21, 2020 | In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan ... |
| CVE-2020-4988 | CRITICAL | 9.8 | 1.4% | Dec 21, 2020 | Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and caus... |
| CVE-2020-4870 | HIGH | 7.5 | 1.7% | Dec 21, 2020 | IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications... |
| CVE-2020-4843 | MEDIUM | 4.3 | 0.5% | Dec 21, 2020 | IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authen... |
| CVE-2020-4842 | MEDIUM | 4.9 | 1.1% | Dec 21, 2020 | IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical ... |
| CVE-2020-4841 | MEDIUM | 5.9 | 1.2% | Dec 21, 2020 | IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to ... |
| CVE-2020-4840 | MEDIUM | 6.1 | 0.9% | Dec 21, 2020 | IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack... |
| CVE-2020-4794 | MEDIUM | 5.4 | 0.8% | Dec 21, 2020 | IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now