2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4082 | MEDIUM | 5.4 | 0.7% | Mar 5, 2020 | The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplie... |
| CVE-2020-5250 | MEDIUM | 6.3 | 0.9% | Mar 5, 2020 | In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the ... |
| CVE-2020-8994 | MEDIUM | 6.8 | 0.6% | Mar 5, 2020 | An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing t... |
| CVE-2020-10107 | MEDIUM | 5.4 | 0.5% | Mar 5, 2020 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCo... |
| CVE-2020-10105 | MEDIUM | 5.3 | 0.9% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS... |
| CVE-2020-10104 | MEDIUM | 4.3 | 0.8% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user ... |
| CVE-2020-10103 | MEDIUM | 5.4 | 0.5% | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t... |
| CVE-2020-10102 | MEDIUM | 5.3 | 0.7% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would ... |
| CVE-2020-10100 | MEDIUM | 6.5 | 0.9% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It allows for users to view ticket customer details associated with s... |
| CVE-2020-10099 | MEDIUM | 5.4 | 0.5% | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t... |
| CVE-2020-10098 | MEDIUM | 5.4 | 0.5% | Mar 5, 2020 | An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through t... |
| CVE-2020-10097 | MEDIUM | 5.3 | 0.9% | Mar 5, 2020 | An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal app... |
| CVE-2020-8660 | MEDIUM | 5.3 | 0.6% | Mar 4, 2020 | CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) ... |
| CVE-2020-8664 | MEDIUM | 5.3 | 1.3% | Mar 4, 2020 | CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same s... |
| CVE-2020-9371 | MEDIUM | 4.8 | 3.6% | Mar 4, 2020 | Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php ... |
| CVE-2020-3193 | MEDIUM | 5.3 | 1.1% | Mar 4, 2020 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent... |
| CVE-2020-3192 | MEDIUM | 6.1 | 0.8% | Mar 4, 2020 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent... |
| CVE-2020-3190 | MEDIUM | 5.8 | 1.3% | Mar 4, 2020 | A vulnerability in the IPsec packet processor of Cisco IOS XR Software could allow an unauthenticated remote attacker to... |
| CVE-2020-3185 | MEDIUM | 5.4 | 0.6% | Mar 4, 2020 | A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an authen... |
| CVE-2020-3182 | MEDIUM | 4.3 | 0.5% | Mar 4, 2020 | A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow ... |
| CVE-2020-3181 | MEDIUM | 6.5 | 1.5% | Mar 4, 2020 | A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in Cisco AsyncOS Softw... |
| CVE-2020-3176 | MEDIUM | 6.7 | 0.4% | Mar 4, 2020 | A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on ... |
| CVE-2020-3164 | MEDIUM | 5.3 | 1.3% | Mar 4, 2020 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco W... |
| CVE-2020-3157 | MEDIUM | 5.4 | 0.6% | Mar 4, 2020 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2020-9364 | MEDIUM | 5.3 | 3.1% | Mar 4, 2020 | An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now