2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7052 | MEDIUM | 6.5 | 1.9% | Jan 24, 2020 | CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a r... |
| CVE-2020-7937 | MEDIUM | 5.4 | 0.8% | Jan 23, 2020 | An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScr... |
| CVE-2020-7936 | MEDIUM | 6.1 | 0.9% | Jan 23, 2020 | An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a ... |
| CVE-2020-6843 | MEDIUM | 4.8 | 2.4% | Jan 23, 2020 | Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-839... |
| CVE-2020-7210 | MEDIUM | 4.3 | 1.0% | Jan 23, 2020 | Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts. |
| CVE-2020-5217 | MEDIUM | 5.8 | 1.8% | Jan 23, 2020 | In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1... |
| CVE-2020-5216 | MEDIUM | 5.8 | 1.1% | Jan 23, 2020 | In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2... |
| CVE-2020-5223 | MEDIUM | 4.4 | 0.7% | Jan 23, 2020 | In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain co... |
| CVE-2020-7915 | MEDIUM | 4.8 | 0.7% | Jan 22, 2020 | An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator. |
| CVE-2020-7228 | MEDIUM | 5.4 | 1.0% | Jan 22, 2020 | The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present... |
| CVE-2020-1788 | MEDIUM | 5.5 | 0.6% | Jan 21, 2020 | Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. ... |
| CVE-2020-1840 | MEDIUM | 6 | 0.2% | Jan 21, 2020 | HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulner... |
| CVE-2020-5202 | MEDIUM | 5.5 | 0.5% | Jan 21, 2020 | apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /u... |
| CVE-2020-6857 | MEDIUM | 5.5 | 1.0% | Jan 21, 2020 | CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT... |
| CVE-2020-7470 | MEDIUM | 4.8 | 0.6% | Jan 21, 2020 | Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login wi... |
| CVE-2020-7239 | MEDIUM | 6.1 | 1.4% | Jan 21, 2020 | The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a cha... |
| CVE-2020-7249 | MEDIUM | 4.8 | 0.6% | Jan 21, 2020 | SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a success... |
| CVE-2020-7215 | MEDIUM | 5.5 | 0.3% | Jan 20, 2020 | An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 befor... |
| CVE-2020-7236 | MEDIUM | 6.1 | 0.7% | Jan 19, 2020 | UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section). |
| CVE-2020-7235 | MEDIUM | 6.1 | 0.7% | Jan 19, 2020 | UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title). |
| CVE-2020-7234 | MEDIUM | 4.8 | 0.6% | Jan 19, 2020 | Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wire... |
| CVE-2020-7231 | MEDIUM | 5.3 | 1.0% | Jan 19, 2020 | Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is ... |
| CVE-2020-7227 | MEDIUM | 6.5 | 1.3% | Jan 18, 2020 | Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remot... |
| CVE-2020-7222 | MEDIUM | 5.3 | 1.3% | Jan 18, 2020 | An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with ... |
| CVE-2020-7104 | MEDIUM | 6.1 | 1.6% | Jan 17, 2020 | The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions paramete... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now