2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9338 | MEDIUM | 5.4 | 0.5% | Feb 22, 2020 | SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field. |
| CVE-2020-9336 | MEDIUM | 5.4 | 0.5% | Feb 22, 2020 | fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field... |
| CVE-2020-9329 | MEDIUM | 5.9 | 0.7% | Feb 21, 2020 | Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go ... |
| CVE-2020-5326 | MEDIUM | 5.3 | 0.3% | Feb 21, 2020 | Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot In... |
| CVE-2020-5324 | MEDIUM | 4.4 | 0.3% | Feb 21, 2020 | Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is li... |
| CVE-2020-5533 | MEDIUM | 6.1 | 0.8% | Feb 21, 2020 | Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arb... |
| CVE-2020-8960 | MEDIUM | 6.1 | 0.9% | Feb 20, 2020 | Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS. |
| CVE-2020-9320 | MEDIUM | 5.5 | 2.8% | Feb 20, 2020 | Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before ... |
| CVE-2020-9003 | MEDIUM | 5.4 | 1.0% | Feb 20, 2020 | A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation... |
| CVE-2020-6977 | MEDIUM | 6.8 | 0.4% | Feb 20, 2020 | A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specia... |
| CVE-2020-7942 | MEDIUM | 6.5 | 0.8% | Feb 19, 2020 | Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the syste... |
| CVE-2020-3163 | MEDIUM | 5.9 | 0.9% | Feb 19, 2020 | A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remot... |
| CVE-2020-3160 | MEDIUM | 5.3 | 1.2% | Feb 19, 2020 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could ... |
| CVE-2020-3159 | MEDIUM | 6.1 | 0.8% | Feb 19, 2020 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t... |
| CVE-2020-3156 | MEDIUM | 6.1 | 1.0% | Feb 19, 2020 | A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated remote attacke... |
| CVE-2020-3154 | MEDIUM | 4.9 | 0.9% | Feb 19, 2020 | A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute... |
| CVE-2020-3153 | MEDIUM | 6.5 | 27.5% | Feb 19, 2020 | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authent... |
| CVE-2020-3138 | MEDIUM | 6.7 | 0.2% | Feb 19, 2020 | A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenti... |
| CVE-2020-3132 | MEDIUM | 5.9 | 1.5% | Feb 19, 2020 | A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)... |
| CVE-2020-3113 | MEDIUM | 5.4 | 0.6% | Feb 19, 2020 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent... |
| CVE-2020-8824 | MEDIUM | 5.4 | 0.6% | Feb 19, 2020 | Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed De... |
| CVE-2020-4230 | MEDIUM | 6.7 | 0.4% | Feb 19, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privil... |
| CVE-2020-4200 | MEDIUM | 6.5 | 1.6% | Feb 19, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated atta... |
| CVE-2020-4161 | MEDIUM | 6.5 | 1.4% | Feb 19, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a ... |
| CVE-2020-8633 | MEDIUM | 5.3 | 1.0% | Feb 18, 2020 | An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calend... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now