2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-23868MEDIUM5.4NeDi 1.9C allows inc/rt-popup.php d XSS.
CVE-2020-9368HIGH7.5The Module Olea Gift On Order module through 5.0.8 for PrestaShop enables an unauthenticated user to read arbitrary file...
CVE-2020-8236MEDIUM6.8A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two ...
CVE-2020-8183HIGH7.5A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initi...
CVE-2020-8173LOW2.2A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter ...
CVE-2020-6014MEDIUM6.5Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83...
CVE-2020-5658HIGH7.5Resource Management Errors vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 Et...
CVE-2020-5657MEDIUM6.5Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl...
CVE-2020-5656CRITICAL9.8Improper access control vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 Ether...
CVE-2020-5655HIGH7.5NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 Eth...
CVE-2020-5654HIGH7.5Session fixation vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP ...
CVE-2020-5653CRITICAL9.8Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP N...
CVE-2020-5652HIGH7.5Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 ...
CVE-2020-28046HIGH7.8An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal ...
CVE-2020-28045HIGH7.8An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and ...
CVE-2020-28044MEDIUM6.8An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in manage...
CVE-2020-28043HIGH7.5MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
CVE-2020-28042MEDIUM5.3ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken functio...
CVE-2020-28041MEDIUM6.5The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate wi...
CVE-2020-28040MEDIUM4.3WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
CVE-2020-28039CRITICAL9.1is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not p...
CVE-2020-28038MEDIUM6.1WordPress before 5.5.2 allows stored XSS via post slugs.
CVE-2020-28037CRITICAL9.8is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is alre...
CVE-2020-28036CRITICAL9.8wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to...
CVE-2020-28035CRITICAL9.8WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now