2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-20139 | MEDIUM | 6.1 | 1.6% | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table ... |
| CVE-2020-20138 | MEDIUM | 6.1 | 3.3% | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4. |
| CVE-2020-12523 | CRITICAL | 9.1 | 0.9% | Dec 17, 2020 | On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled ... |
| CVE-2020-12522 | CRITICAL | 9.8 | 2.9% | Dec 17, 2020 | The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafte... |
| CVE-2020-12521 | MEDIUM | 6.5 | 0.5% | Dec 17, 2020 | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high... |
| CVE-2020-12519 | CRITICAL | 9.8 | 0.9% | Dec 17, 2020 | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to ope... |
| CVE-2020-12518 | MEDIUM | 5.5 | 0.7% | Dec 17, 2020 | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by readin... |
| CVE-2020-12517 | CRITICAL | 9 | 1.1% | Dec 17, 2020 | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed m... |
| CVE-2020-8466 | CRITICAL | 9.8 | 63.7% | Dec 17, 2020 | A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved pas... |
| CVE-2020-8465 | CRITICAL | 9.8 | 2.6% | Dec 17, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate sy... |
| CVE-2020-8464 | HIGH | 7.5 | 6.3% | Dec 17, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests... |
| CVE-2020-8463 | HIGH | 7.5 | 5.9% | Dec 17, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a glob... |
| CVE-2020-8462 | MEDIUM | 4.8 | 1.1% | Dec 17, 2020 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow a... |
| CVE-2020-8461 | HIGH | 8.8 | 1.1% | Dec 17, 2020 | A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an at... |
| CVE-2020-27010 | MEDIUM | 4.8 | 0.7% | Dec 17, 2020 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow a... |
| CVE-2020-35545 | CRITICAL | 9.8 | 3.8% | Dec 17, 2020 | Time-based SQL injection exists in Spotweb 1.4.9 via the query string. |
| CVE-2020-26276 | CRITICAL | 9.8 | 2.2% | Dec 17, 2020 | Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsi... |
| CVE-2020-4846 | LOW | 2.7 | 1.0% | Dec 17, 2020 | IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a de... |
| CVE-2020-4845 | MEDIUM | 5.4 | 0.6% | Dec 17, 2020 | IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2020-35491 | HIGH | 8.1 | 9.5% | Dec 17, 2020 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-35490 | HIGH | 8.1 | 7.7% | Dec 17, 2020 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-35489 | CRITICAL | 10 | 89.3% | Dec 17, 2020 | The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote cod... |
| CVE-2020-15294 | HIGH | 7 | 0.3% | Dec 17, 2020 | Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results ... |
| CVE-2020-15293 | MEDIUM | 5.5 | 0.3% | Dec 17, 2020 | Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to ins... |
| CVE-2020-15292 | MEDIUM | 5.5 | 0.3% | Dec 17, 2020 | Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, Int... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now