2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7762MEDIUM6.5This affects the package jsreport-chrome-pdf before 1.10.0.
CVE-2020-7761MEDIUM5.3This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted inva...
CVE-2020-27387HIGH8.8An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access...
CVE-2020-25201HIGH7.5HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cau...
CVE-2020-26207HIGH8DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening ...
CVE-2020-27692HIGH8.8The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within ...
CVE-2020-27691MEDIUM6.1The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Sett...
CVE-2020-27690MEDIUM5.5The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web mana...
CVE-2020-7129HIGH7.2A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3...
CVE-2020-7128CRITICAL9.8A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Pri...
CVE-2020-27689CRITICAL9.8The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credential...
CVE-2020-28049MEDIUM6.3An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time perio...
CVE-2020-8037HIGH7.5The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
CVE-2020-8036HIGH7.5The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.
CVE-2020-22274CRITICAL9.8JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
CVE-2020-22273MEDIUM6.5Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (suc...
CVE-2020-26167CRITICAL9.8In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any acco...
CVE-2020-22278HIGH8.8phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file i...
CVE-2020-22277HIGH8Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
CVE-2020-22276CRITICAL9.8WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
CVE-2020-22275HIGH8.8Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV comma...
CVE-2020-2319MEDIUM6.5Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file o...
CVE-2020-2318MEDIUM6.5Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml fil...
CVE-2020-2317MEDIUM5.4Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cros...
CVE-2020-2316MEDIUM5.4Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now