2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14244CRITICAL9.8A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by ...
CVE-2020-29227CRITICAL9.8An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack...
CVE-2020-17513MEDIUM5.3In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable...
CVE-2020-17511MEDIUM6.5In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in ...
CVE-2020-35236MEDIUM5.3The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deleti...
CVE-2020-5665HIGH7.4Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and e...
CVE-2020-5639CRITICAL9.8Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitra...
CVE-2020-5637MEDIUM6.8Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows...
CVE-2020-5636MEDIUM6.8Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specia...
CVE-2020-5635HIGH8.8Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially craft...
CVE-2020-35235HIGH8.8vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder cod...
CVE-2020-35234HIGH7.5The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De...
CVE-2020-9001Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-8999Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-29669HIGH8.8In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This pr...
CVE-2020-35208MEDIUM5.7An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. T...
CVE-2020-35207MEDIUM5.7An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. T...
CVE-2020-35202MEDIUM5.4Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
CVE-2020-35201MEDIUM5.4Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.
CVE-2020-35200MEDIUM6.1Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
CVE-2020-35199MEDIUM5.4Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.
CVE-2020-35176MEDIUM5.3In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even...
CVE-2020-29654HIGH7.8Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.
CVE-2020-29563CRITICAL9.8An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vuln...
CVE-2020-35175MEDIUM5.3Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now