2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9028 | MEDIUM | 6.1 | 0.7% | Feb 17, 2020 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via t... |
| CVE-2020-9025 | MEDIUM | 6.1 | 0.7% | Feb 17, 2020 | Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Vie... |
| CVE-2020-9022 | MEDIUM | 6.1 | 0.7% | Feb 17, 2020 | An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter all... |
| CVE-2020-9016 | MEDIUM | 5.4 | 0.9% | Feb 16, 2020 | Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header. |
| CVE-2020-9013 | MEDIUM | 4.3 | 1.3% | Feb 16, 2020 | Arvato Skillpipe 3.0 allows attackers to bypass intended print restrictions by deleting <div id="watermark"> from the HT... |
| CVE-2020-9012 | MEDIUM | 6.1 | 0.8% | Feb 16, 2020 | A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows ... |
| CVE-2020-9007 | MEDIUM | 5.4 | 0.5% | Feb 16, 2020 | Codoforum 4.8.8 allows self-XSS via the title of a new topic. |
| CVE-2020-8996 | MEDIUM | 4.3 | 1.1% | Feb 16, 2020 | AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwi... |
| CVE-2020-7050 | MEDIUM | 5.4 | 0.5% | Feb 15, 2020 | Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to... |
| CVE-2020-8594 | MEDIUM | 5.4 | 1.2% | Feb 14, 2020 | The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key],... |
| CVE-2020-7251 | MEDIUM | 5.5 | 0.2% | Feb 14, 2020 | Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 Feb... |
| CVE-2020-5532 | MEDIUM | 4.3 | 0.9% | Feb 14, 2020 | ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker o... |
| CVE-2020-8992 | MEDIUM | 5.5 | 0.4% | Feb 14, 2020 | ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a de... |
| CVE-2020-8989 | MEDIUM | 5.3 | 1.0% | Feb 13, 2020 | In the Voatz application 2020-01-01 for Android, the amount of data transmitted during a single voter's vote depends on ... |
| CVE-2020-8988 | MEDIUM | 5.9 | 0.9% | Feb 13, 2020 | The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers... |
| CVE-2020-8981 | MEDIUM | 6.1 | 1.1% | Feb 13, 2020 | A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2... |
| CVE-2020-8804 | MEDIUM | 6.5 | 1.4% | Feb 13, 2020 | SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module. |
| CVE-2020-7051 | MEDIUM | 6.1 | 0.8% | Feb 13, 2020 | Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-584... |
| CVE-2020-0028 | MEDIUM | 6.5 | 2.7% | Feb 13, 2020 | In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings.... |
| CVE-2020-0023 | MEDIUM | 5.5 | 0.3% | Feb 13, 2020 | In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth d... |
| CVE-2020-0021 | MEDIUM | 6.5 | 0.8% | Feb 13, 2020 | In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missi... |
| CVE-2020-0020 | MEDIUM | 5.5 | 0.1% | Feb 13, 2020 | In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files ... |
| CVE-2020-0018 | MEDIUM | 4.4 | 0.2% | Feb 13, 2020 | In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lea... |
| CVE-2020-0017 | MEDIUM | 4.4 | 0.2% | Feb 13, 2020 | In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users... |
| CVE-2020-0014 | MEDIUM | 5.5 | 1.0% | Feb 13, 2020 | It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. Thi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now