2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3169 | MEDIUM | 6.7 | 0.4% | Feb 26, 2020 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary comm... |
| CVE-2020-3166 | MEDIUM | 6.7 | 0.3% | Feb 26, 2020 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrar... |
| CVE-2020-8952 | MEDIUM | 6.1 | 0.7% | Feb 26, 2020 | Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the logout.jsp timeOut parameter. |
| CVE-2020-8951 | MEDIUM | 5.4 | 0.6% | Feb 26, 2020 | Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the C... |
| CVE-2020-9337 | MEDIUM | 6.5 | 0.5% | Feb 26, 2020 | In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request. |
| CVE-2020-9407 | MEDIUM | 5.3 | 0.5% | Feb 26, 2020 | IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COO... |
| CVE-2020-9405 | MEDIUM | 6.1 | 0.6% | Feb 26, 2020 | IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page. |
| CVE-2020-9393 | MEDIUM | 6.1 | 0.9% | Feb 25, 2020 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS. |
| CVE-2020-9379 | MEDIUM | 6.5 | 0.9% | Feb 25, 2020 | The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB4962... |
| CVE-2020-9391 | MEDIUM | 5.5 | 0.5% | Feb 25, 2020 | An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top by... |
| CVE-2020-9019 | MEDIUM | 6.1 | 1.6% | Feb 25, 2020 | The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Descr... |
| CVE-2020-9018 | MEDIUM | 5.3 | 0.4% | Feb 25, 2020 | LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user. |
| CVE-2020-9008 | MEDIUM | 5.4 | 0.6% | Feb 25, 2020 | Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web... |
| CVE-2020-9335 | MEDIUM | 4.8 | 1.4% | Feb 25, 2020 | Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploita... |
| CVE-2020-9334 | MEDIUM | 5.4 | 0.8% | Feb 25, 2020 | A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitatio... |
| CVE-2020-8793 | MEDIUM | 4.7 | 0.9% | Feb 25, 2020 | OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combi... |
| CVE-2020-9382 | MEDIUM | 5.4 | 1.0% | Feb 24, 2020 | An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for th... |
| CVE-2020-1935 | MEDIUM | 4.8 | 9.4% | Feb 24, 2020 | In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach t... |
| CVE-2020-8130 | MEDIUM | 6.4 | 1.4% | Feb 24, 2020 | There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that be... |
| CVE-2020-5188 | MEDIUM | 6.5 | 1.8% | Feb 24, 2020 | DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. |
| CVE-2020-5186 | MEDIUM | 5.4 | 0.9% | Feb 24, 2020 | DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). |
| CVE-2020-9351 | MEDIUM | 5.3 | 1.1% | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerCons... |
| CVE-2020-9350 | MEDIUM | 5.4 | 0.5% | Feb 23, 2020 | Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly. |
| CVE-2020-9342 | MEDIUM | 5.5 | 1.6% | Feb 22, 2020 | The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a ... |
| CVE-2020-9339 | MEDIUM | 5.4 | 0.6% | Feb 22, 2020 | SOPlanning 1.45 allows XSS via the Name or Comment to status.php. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now