2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14244 | CRITICAL | 9.8 | 3.0% | Dec 14, 2020 | A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by ... |
| CVE-2020-29227 | CRITICAL | 9.8 | 16.8% | Dec 14, 2020 | An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack... |
| CVE-2020-17513 | MEDIUM | 5.3 | 4.3% | Dec 14, 2020 | In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable... |
| CVE-2020-17511 | MEDIUM | 6.5 | 2.5% | Dec 14, 2020 | In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in ... |
| CVE-2020-35236 | MEDIUM | 5.3 | 1.2% | Dec 14, 2020 | The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deleti... |
| CVE-2020-5665 | HIGH | 7.4 | 1.0% | Dec 14, 2020 | Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and e... |
| CVE-2020-5639 | CRITICAL | 9.8 | 5.0% | Dec 14, 2020 | Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitra... |
| CVE-2020-5637 | MEDIUM | 6.8 | 0.4% | Dec 14, 2020 | Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows... |
| CVE-2020-5636 | MEDIUM | 6.8 | 0.7% | Dec 14, 2020 | Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specia... |
| CVE-2020-5635 | HIGH | 8.8 | 1.0% | Dec 14, 2020 | Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially craft... |
| CVE-2020-35235 | HIGH | 8.8 | 18.0% | Dec 14, 2020 | vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder cod... |
| CVE-2020-35234 | HIGH | 7.5 | 63.4% | Dec 14, 2020 | The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De... |
| CVE-2020-9001 | — | — | — | Dec 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-8999 | — | — | — | Dec 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-29669 | HIGH | 8.8 | 4.9% | Dec 14, 2020 | In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This pr... |
| CVE-2020-35208 | MEDIUM | 5.7 | 0.5% | Dec 12, 2020 | An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. T... |
| CVE-2020-35207 | MEDIUM | 5.7 | 0.5% | Dec 12, 2020 | An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. T... |
| CVE-2020-35202 | MEDIUM | 5.4 | 0.7% | Dec 12, 2020 | Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS. |
| CVE-2020-35201 | MEDIUM | 5.4 | 0.7% | Dec 12, 2020 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS. |
| CVE-2020-35200 | MEDIUM | 6.1 | 0.9% | Dec 12, 2020 | Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS. |
| CVE-2020-35199 | MEDIUM | 5.4 | 0.6% | Dec 12, 2020 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS. |
| CVE-2020-35176 | MEDIUM | 5.3 | 1.8% | Dec 12, 2020 | In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even... |
| CVE-2020-29654 | HIGH | 7.8 | 0.4% | Dec 12, 2020 | Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account. |
| CVE-2020-29563 | CRITICAL | 9.8 | 2.9% | Dec 12, 2020 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vuln... |
| CVE-2020-35175 | MEDIUM | 5.3 | 0.9% | Dec 11, 2020 | Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now