2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26077 | MEDIUM | 4.3 | 0.7% | Nov 18, 2020 | A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticat... |
| CVE-2020-26076 | HIGH | 7.5 | 1.3% | Nov 18, 2020 | A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensit... |
| CVE-2020-26075 | HIGH | 8.8 | 1.6% | Nov 18, 2020 | A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker ... |
| CVE-2020-26072 | HIGH | 8.7 | 1.0% | Nov 18, 2020 | A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker ... |
| CVE-2020-26068 | MEDIUM | 6.5 | 0.7% | Nov 18, 2020 | A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authentic... |
| CVE-2020-28367 | HIGH | 7.5 | 2.4% | Nov 18, 2020 | Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time ... |
| CVE-2020-28366 | HIGH | 7.5 | 2.2% | Nov 18, 2020 | Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time ... |
| CVE-2020-28362 | HIGH | 7.5 | 3.8% | Nov 18, 2020 | Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. |
| CVE-2020-28091 | HIGH | 7.5 | 3.8% | Nov 18, 2020 | cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame... |
| CVE-2020-26933 | MEDIUM | 6 | 0.3% | Nov 18, 2020 | Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.... |
| CVE-2020-26554 | MEDIUM | 6.1 | 1.0% | Nov 18, 2020 | REDDOXX MailDepot 2033 (aka 2.3.3022) allows XSS via an incoming HTML e-mail message. |
| CVE-2020-28005 | MEDIUM | 6.5 | 1.8% | Nov 18, 2020 | httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffe... |
| CVE-2020-26884 | MEDIUM | 6.1 | 0.8% | Nov 18, 2020 | RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could ... |
| CVE-2020-25406 | HIGH | 7.3 | 0.9% | Nov 18, 2020 | app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files. |
| CVE-2020-24297 | HIGH | 8.8 | 3.6% | Nov 18, 2020 | httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS com... |
| CVE-2020-6016 | CRITICAL | 9.8 | 5.8% | Nov 18, 2020 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in ... |
| CVE-2020-28724 | MEDIUM | 6.1 | 1.7% | Nov 18, 2020 | Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL. |
| CVE-2020-7564 | HIGH | 8.8 | 1.1% | Nov 18, 2020 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server... |
| CVE-2020-7563 | HIGH | 8.8 | 1.1% | Nov 18, 2020 | A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premi... |
| CVE-2020-7562 | HIGH | 8.1 | 0.9% | Nov 18, 2020 | A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premiu... |
| CVE-2020-28361 | MEDIUM | 5.4 | 1.1% | Nov 18, 2020 | Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allow... |
| CVE-2020-24723 | MEDIUM | 4.8 | 1.0% | Nov 18, 2020 | Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & L... |
| CVE-2020-28917 | MEDIUM | 6.5 | 0.5% | Nov 18, 2020 | An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves... |
| CVE-2020-28915 | MEDIUM | 5.8 | 0.4% | Nov 18, 2020 | A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local... |
| CVE-2020-28183 | CRITICAL | 9.8 | 2.5% | Nov 17, 2020 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to proce... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now