2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7762 | MEDIUM | 6.5 | 1.6% | Nov 5, 2020 | This affects the package jsreport-chrome-pdf before 1.10.0. |
| CVE-2020-7761 | MEDIUM | 5.3 | 1.6% | Nov 5, 2020 | This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted inva... |
| CVE-2020-27387 | HIGH | 8.8 | 18.5% | Nov 5, 2020 | An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access... |
| CVE-2020-25201 | HIGH | 7.5 | 2.6% | Nov 4, 2020 | HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cau... |
| CVE-2020-26207 | HIGH | 8 | 2.0% | Nov 4, 2020 | DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening ... |
| CVE-2020-27692 | HIGH | 8.8 | 0.5% | Nov 4, 2020 | The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within ... |
| CVE-2020-27691 | MEDIUM | 6.1 | 0.7% | Nov 4, 2020 | The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Sett... |
| CVE-2020-27690 | MEDIUM | 5.5 | 0.4% | Nov 4, 2020 | The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web mana... |
| CVE-2020-7129 | HIGH | 7.2 | 2.6% | Nov 4, 2020 | A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3... |
| CVE-2020-7128 | CRITICAL | 9.8 | 2.1% | Nov 4, 2020 | A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Pri... |
| CVE-2020-27689 | CRITICAL | 9.8 | 2.2% | Nov 4, 2020 | The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credential... |
| CVE-2020-28049 | MEDIUM | 6.3 | 0.4% | Nov 4, 2020 | An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time perio... |
| CVE-2020-8037 | HIGH | 7.5 | 3.1% | Nov 4, 2020 | The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. |
| CVE-2020-8036 | HIGH | 7.5 | 1.4% | Nov 4, 2020 | The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way. |
| CVE-2020-22274 | CRITICAL | 9.8 | 1.6% | Nov 4, 2020 | JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile. |
| CVE-2020-22273 | MEDIUM | 6.5 | 0.4% | Nov 4, 2020 | Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (suc... |
| CVE-2020-26167 | CRITICAL | 9.8 | 3.5% | Nov 4, 2020 | In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any acco... |
| CVE-2020-22278 | HIGH | 8.8 | 1.5% | Nov 4, 2020 | phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file i... |
| CVE-2020-22277 | HIGH | 8 | 1.8% | Nov 4, 2020 | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. |
| CVE-2020-22276 | CRITICAL | 9.8 | 3.0% | Nov 4, 2020 | WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. |
| CVE-2020-22275 | HIGH | 8.8 | 2.1% | Nov 4, 2020 | Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV comma... |
| CVE-2020-2319 | MEDIUM | 6.5 | 1.0% | Nov 4, 2020 | Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file o... |
| CVE-2020-2318 | MEDIUM | 6.5 | 1.0% | Nov 4, 2020 | Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml fil... |
| CVE-2020-2317 | MEDIUM | 5.4 | 0.9% | Nov 4, 2020 | Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cros... |
| CVE-2020-2316 | MEDIUM | 5.4 | 0.7% | Nov 4, 2020 | Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now