2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13958 | HIGH | 7.8 | 2.7% | Nov 17, 2020 | A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks po... |
| CVE-2020-27558 | MEDIUM | 6.5 | 1.1% | Nov 17, 2020 | Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video st... |
| CVE-2020-27557 | MEDIUM | 5.5 | 0.3% | Nov 17, 2020 | Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to g... |
| CVE-2020-27556 | MEDIUM | 5.3 | 1.0% | Nov 17, 2020 | A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to conne... |
| CVE-2020-27555 | CRITICAL | 9.8 | 2.5% | Nov 17, 2020 | Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers... |
| CVE-2020-27554 | HIGH | 7.5 | 0.7% | Nov 17, 2020 | Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists whi... |
| CVE-2020-27553 | HIGH | 7.5 | 1.5% | Nov 17, 2020 | In BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoo... |
| CVE-2020-25798 | MEDIUM | 5.4 | 0.6% | Nov 17, 2020 | A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users w... |
| CVE-2020-21665 | HIGH | 7.2 | 0.9% | Nov 17, 2020 | In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be pas... |
| CVE-2020-7841 | HIGH | 8.8 | 1.5% | Nov 17, 2020 | Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution whe... |
| CVE-2020-28688 | HIGH | 8.8 | 11.9% | Nov 17, 2020 | The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo... |
| CVE-2020-28687 | HIGH | 8.8 | 11.9% | Nov 17, 2020 | The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upl... |
| CVE-2020-28647 | MEDIUM | 5.4 | 1.4% | Nov 17, 2020 | In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a... |
| CVE-2020-25746 | MEDIUM | 4.6 | 0.3% | Nov 17, 2020 | QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obta... |
| CVE-2020-7774 | CRITICAL | 9.8 | 69.1% | Nov 17, 2020 | The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. |
| CVE-2020-27131 | CRITICAL | 9.8 | 87.7% | Nov 17, 2020 | Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unau... |
| CVE-2020-27130 | CRITICAL | 9.1 | 65.9% | Nov 17, 2020 | A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive in... |
| CVE-2020-27125 | CRITICAL | 9.8 | 1.7% | Nov 17, 2020 | A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive informatio... |
| CVE-2020-27192 | HIGH | 7.8 | 0.4% | Nov 17, 2020 | BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allo... |
| CVE-2020-25833 | MEDIUM | 4.8 | 0.5% | Nov 17, 2020 | Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. ... |
| CVE-2020-25832 | MEDIUM | 5.4 | 0.5% | Nov 17, 2020 | Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability cou... |
| CVE-2020-25705 | HIGH | 7.4 | 6.7% | Nov 17, 2020 | A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off... |
| CVE-2020-15349 | HIGH | 7.8 | 0.7% | Nov 17, 2020 | BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool i... |
| CVE-2020-14389 | HIGH | 8.1 | 0.8% | Nov 17, 2020 | It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources... |
| CVE-2020-11851 | CRITICAL | 9.8 | 2.8% | Nov 17, 2020 | Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now