2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29509 | MEDIUM | 5.6 | 2.1% | Dec 14, 2020 | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes ... |
| CVE-2020-29304 | MEDIUM | 6.1 | 5.5% | Dec 14, 2020 | A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and p... |
| CVE-2020-29303 | MEDIUM | 6.1 | 1.9% | Dec 14, 2020 | A cross-site scripting (XSS) vulnerability in the SabaiApp Directories Pro plugin 1.3.45 for WordPress allows remote att... |
| CVE-2020-28861 | MEDIUM | 5.3 | 2.3% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV ... |
| CVE-2020-28860 | HIGH | 8.8 | 2.2% | Dec 14, 2020 | OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating i... |
| CVE-2020-27252 | HIGH | 8.1 | 3.7% | Dec 14, 2020 | Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update sys... |
| CVE-2020-25187 | CRITICAL | 9.8 | 3.9% | Dec 14, 2020 | Medtronic MyCareLink Smart 25000 is vulnerable when an authenticated attacker runs a debug command, which can be sent... |
| CVE-2020-25183 | HIGH | 8.8 | 0.8% | Dec 14, 2020 | Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authentica... |
| CVE-2020-20184 | CRITICAL | 9.8 | 2.7% | Dec 14, 2020 | GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting... |
| CVE-2020-20183 | HIGH | 7.5 | 1.0% | Dec 14, 2020 | Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier al... |
| CVE-2020-16104 | HIGH | 7.2 | 0.9% | Dec 14, 2020 | SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit... |
| CVE-2020-16103 | HIGH | 8.8 | 2.2% | Dec 14, 2020 | Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote ... |
| CVE-2020-16102 | HIGH | 8.2 | 1.0% | Dec 14, 2020 | Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to cr... |
| CVE-2020-28859 | MEDIUM | 6.1 | 0.8% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple par... |
| CVE-2020-28858 | HIGH | 8.8 | 1.1% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the applica... |
| CVE-2020-28857 | MEDIUM | 6.1 | 1.5% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple pa... |
| CVE-2020-20136 | CRITICAL | 9.8 | 1.5% | Dec 14, 2020 | QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to inse... |
| CVE-2020-35338 | CRITICAL | 9.8 | 11.7% | Dec 14, 2020 | The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier... |
| CVE-2020-28856 | HIGH | 7.5 | 2.5% | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP ... |
| CVE-2020-25179 | CRITICAL | 9.8 | 1.4% | Dec 14, 2020 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net... |
| CVE-2020-25175 | CRITICAL | 9.8 | 1.1% | Dec 14, 2020 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the net... |
| CVE-2020-15733 | MEDIUM | 6.5 | 0.6% | Dec 14, 2020 | An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to... |
| CVE-2020-35382 | HIGH | 7.2 | 1.0% | Dec 14, 2020 | SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user. |
| CVE-2020-35378 | CRITICAL | 9.8 | 2.0% | Dec 14, 2020 | SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands ... |
| CVE-2020-14268 | CRITICAL | 9.8 | 2.2% | Dec 14, 2020 | A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now