2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29364 | MEDIUM | 4.8 | 0.6% | Nov 30, 2020 | In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news tit... |
| CVE-2020-28926 | CRITICAL | 9.8 | 14.3% | Nov 30, 2020 | ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to t... |
| CVE-2020-25537 | CRITICAL | 9.8 | 1.8% | Nov 30, 2020 | File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain serv... |
| CVE-2020-4900 | MEDIUM | 5.5 | 0.3% | Nov 30, 2020 | IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a ... |
| CVE-2020-4696 | MEDIUM | 4.3 | 0.7% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated use... |
| CVE-2020-4627 | CRITICAL | 9 | 1.6% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitr... |
| CVE-2020-4626 | MEDIUM | 4.3 | 1.0% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1 (CP4S) could reveal sensitive information about the internal network to an authentica... |
| CVE-2020-4625 | MEDIUM | 5.3 | 1.5% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the fa... |
| CVE-2020-4624 | MEDIUM | 5.3 | 0.7% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could al... |
| CVE-2020-29384 | MEDIUM | 5.5 | 1.0% | Nov 30, 2020 | An issue was discovered in PNGOUT 2020-01-15. When compressing a crafted PNG file, it encounters an integer overflow. |
| CVE-2020-28978 | MEDIUM | 5.3 | 15.3% | Nov 30, 2020 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a... |
| CVE-2020-28977 | MEDIUM | 5.3 | 15.3% | Nov 30, 2020 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a... |
| CVE-2020-28976 | MEDIUM | 5.3 | 26.0% | Nov 30, 2020 | The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make... |
| CVE-2020-27660 | CRITICAL | 9.8 | 4.6% | Nov 30, 2020 | SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute a... |
| CVE-2020-27659 | MEDIUM | 4.8 | 5.1% | Nov 30, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to i... |
| CVE-2020-29127 | CRITICAL | 9.8 | 4.4% | Nov 30, 2020 | An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as... |
| CVE-2020-25624 | MEDIUM | 5 | 0.6% | Nov 30, 2020 | hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver. |
| CVE-2020-29383 | HIGH | 7.8 | 0.3% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. A hardcoded RSA private key (sp... |
| CVE-2020-29382 | HIGH | 7.8 | 0.3% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices... |
| CVE-2020-29381 | CRITICAL | 9.8 | 2.3% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a... |
| CVE-2020-29380 | MEDIUM | 5.9 | 0.5% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a... |
| CVE-2020-29379 | MEDIUM | 5.5 | 0.3% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating ... |
| CVE-2020-29378 | HIGH | 8.8 | 1.1% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a... |
| CVE-2020-29377 | CRITICAL | 9.8 | 1.3% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 OLT devices. The string K0LTdi@gnos312$ is compared to the password pro... |
| CVE-2020-29376 | CRITICAL | 9.8 | 1.1% | Nov 29, 2020 | An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now