2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29135 | MEDIUM | 4.1 | 0.6% | Nov 27, 2020 | cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567). |
| CVE-2020-29133 | MEDIUM | 6.1 | 1.1% | Nov 27, 2020 | jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename... |
| CVE-2020-12262 | MEDIUM | 5.4 | 1.5% | Nov 27, 2020 | Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= ... |
| CVE-2020-29130 | MEDIUM | 4.3 | 1.8% | Nov 26, 2020 | slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even i... |
| CVE-2020-29129 | MEDIUM | 4.3 | 1.4% | Nov 26, 2020 | ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if... |
| CVE-2020-26936 | HIGH | 8.8 | 0.4% | Nov 26, 2020 | Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack. |
| CVE-2020-29043 | HIGH | 7.5 | 1.4% | Nov 26, 2020 | An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?to... |
| CVE-2020-29042 | LOW | 3.7 | 1.1% | Nov 26, 2020 | An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of c... |
| CVE-2020-29065 | — | — | — | Nov 26, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2020-27663 | MEDIUM | 4.3 | 0.9% | Nov 26, 2020 | In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows... |
| CVE-2020-27662 | MEDIUM | 4.3 | 0.7% | Nov 26, 2020 | In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an atta... |
| CVE-2020-27207 | HIGH | 7.5 | 1.6% | Nov 26, 2020 | Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite... |
| CVE-2020-13886 | MEDIUM | 5.3 | 4.3% | Nov 26, 2020 | Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?pag... |
| CVE-2020-7779 | HIGH | 7.5 | 1.7% | Nov 26, 2020 | All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted in... |
| CVE-2020-7778 | HIGH | 7.3 | 2.4% | Nov 26, 2020 | This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an ... |
| CVE-2020-29128 | CRITICAL | 9.8 | 2.3% | Nov 26, 2020 | petl before 1.68, in some configurations, allows resolution of entities in an XML document. |
| CVE-2020-27255 | HIGH | 7.5 | 3.2% | Nov 26, 2020 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a re... |
| CVE-2020-27253 | HIGH | 7.5 | 1.6% | Nov 26, 2020 | A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could ... |
| CVE-2020-27251 | CRITICAL | 9.8 | 5.5% | Nov 26, 2020 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a re... |
| CVE-2020-25653 | MEDIUM | 6.3 | 0.3% | Nov 26, 2020 | A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw ... |
| CVE-2020-25652 | MEDIUM | 5.5 | 0.4% | Nov 26, 2020 | A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be establish... |
| CVE-2020-25651 | MEDIUM | 6.4 | 0.3% | Nov 26, 2020 | A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in t... |
| CVE-2020-29074 | HIGH | 8.8 | 1.7% | Nov 25, 2020 | scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. |
| CVE-2020-14190 | HIGH | 7.5 | 1.2% | Nov 25, 2020 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-suppl... |
| CVE-2020-14191 | HIGH | 7.5 | 1.2% | Nov 25, 2020 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a De... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now