2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7997 | MEDIUM | 6.1 | 0.7% | Jan 28, 2020 | ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature. |
| CVE-2020-1933 | MEDIUM | 6.1 | 2.8% | Jan 28, 2020 | A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through acti... |
| CVE-2020-1932 | MEDIUM | 6.5 | 1.4% | Jan 28, 2020 | An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Su... |
| CVE-2020-1928 | MEDIUM | 5.3 | 4.0% | Jan 28, 2020 | An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed... |
| CVE-2020-0549 | MEDIUM | 5.5 | 0.6% | Jan 28, 2020 | Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially ... |
| CVE-2020-0548 | MEDIUM | 5.5 | 0.5% | Jan 28, 2020 | Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure ... |
| CVE-2020-8091 | MEDIUM | 6.1 | 5.2% | Jan 27, 2020 | svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cr... |
| CVE-2020-8090 | MEDIUM | 4.8 | 0.6% | Jan 27, 2020 | The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a succes... |
| CVE-2020-5220 | MEDIUM | 5.3 | 0.7% | Jan 27, 2020 | Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data ... |
| CVE-2020-5218 | MEDIUM | 4.3 | 0.6% | Jan 27, 2020 | Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in product... |
| CVE-2020-8003 | MEDIUM | 5.5 | 0.3% | Jan 27, 2020 | A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of ser... |
| CVE-2020-8002 | MEDIUM | 5.5 | 0.3% | Jan 27, 2020 | A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of serv... |
| CVE-2020-7996 | MEDIUM | 6.1 | 1.2% | Jan 26, 2020 | htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header. |
| CVE-2020-7994 | MEDIUM | 6.1 | 1.5% | Jan 26, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web sc... |
| CVE-2020-7990 | MEDIUM | 6.1 | 0.9% | Jan 26, 2020 | Adive Framework 2.0.8 has admin/user/add userName XSS. |
| CVE-2020-7989 | MEDIUM | 6.1 | 0.9% | Jan 26, 2020 | Adive Framework 2.0.8 has admin/user/add userUsername XSS. |
| CVE-2020-3139 | MEDIUM | 5.3 | 1.0% | Jan 26, 2020 | A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Inf... |
| CVE-2020-3136 | MEDIUM | 6.1 | 0.8% | Jan 26, 2020 | A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attac... |
| CVE-2020-3134 | MEDIUM | 6.5 | 1.1% | Jan 26, 2020 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could... |
| CVE-2020-3131 | MEDIUM | 6.5 | 2.2% | Jan 26, 2020 | A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the c... |
| CVE-2020-3129 | MEDIUM | 4.8 | 0.6% | Jan 26, 2020 | A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, r... |
| CVE-2020-3121 | MEDIUM | 6.1 | 1.1% | Jan 26, 2020 | A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an ... |
| CVE-2020-5226 | MEDIUM | 5.4 | 0.5% | Jan 24, 2020 | Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be su... |
| CVE-2020-5225 | MEDIUM | 5.4 | 0.6% | Jan 24, 2020 | Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and se... |
| CVE-2020-7964 | MEDIUM | 5.3 | 1.1% | Jan 24, 2020 | An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutat... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now