2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14271 | MEDIUM | 6.1 | 1.1% | Dec 18, 2020 | HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling ... |
| CVE-2020-14224 | CRITICAL | 9.8 | 2.2% | Dec 18, 2020 | A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthentic... |
| CVE-2020-4080 | MEDIUM | 6.1 | 0.8% | Dec 18, 2020 | HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of me... |
| CVE-2020-5803 | HIGH | 8.1 | 1.7% | Dec 18, 2020 | Relative Path Traversal in Marvell QConvergeConsole GUI 5.5.0.74 allows a remote, authenticated attacker to delete arbit... |
| CVE-2020-27781 | HIGH | 7.1 | 0.3% | Dec 18, 2020 | User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential pr... |
| CVE-2020-17520 | MEDIUM | 6.5 | 1.3% | Dec 18, 2020 | In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verificat... |
| CVE-2020-13535 | HIGH | 7.8 | 0.7% | Dec 18, 2020 | A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker ca... |
| CVE-2020-11974 | CRITICAL | 9.8 | 7.6% | Dec 18, 2020 | In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing my... |
| CVE-2020-13519 | HIGH | 8.8 | 0.6% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A ... |
| CVE-2020-13515 | HIGH | 8.8 | 0.5% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A ... |
| CVE-2020-13514 | HIGH | 8.8 | 0.5% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA... |
| CVE-2020-13513 | HIGH | 8.8 | 0.5% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA... |
| CVE-2020-13512 | HIGH | 8.8 | 0.5% | Dec 18, 2020 | A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CA... |
| CVE-2020-27687 | HIGH | 8.8 | 1.5% | Dec 18, 2020 | ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send... |
| CVE-2020-26280 | HIGH | 8.9 | 1.1% | Dec 18, 2020 | OpenSlides is a free, Web-based presentation and assembly system for managing and projecting agenda, motions, and electi... |
| CVE-2020-20300 | CRITICAL | 9.8 | 8.8% | Dec 18, 2020 | SQL injection vulnerability in the wp_where function in WeiPHP 5.0. |
| CVE-2020-20299 | HIGH | 7.5 | 1.5% | Dec 18, 2020 | WeiPHP 5.0 does not properly restrict access to pages, related to using POST. |
| CVE-2020-20298 | CRITICAL | 9.8 | 2.7% | Dec 18, 2020 | Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 ... |
| CVE-2020-20285 | MEDIUM | 5.4 | 1.6% | Dec 18, 2020 | There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php |
| CVE-2020-20277 | CRITICAL | 9.8 | 25.2% | Dec 18, 2020 | There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server ver... |
| CVE-2020-20276 | CRITICAL | 9.8 | 3.3% | Dec 18, 2020 | An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10... |
| CVE-2020-26251 | MEDIUM | 4.7 | 0.4% | Dec 18, 2020 | Open Zaak is a modern, open-source data- and services-layer to enable zaakgericht werken, a Dutch approach to case manag... |
| CVE-2020-4764 | MEDIUM | 6.5 | 0.4% | Dec 18, 2020 | IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
| CVE-2020-25901 | MEDIUM | 6.1 | 5.1% | Dec 18, 2020 | Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we... |
| CVE-2020-25495 | MEDIUM | 6.1 | 8.1% | Dec 18, 2020 | A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now