2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23868 | MEDIUM | 5.4 | 0.5% | Nov 2, 2020 | NeDi 1.9C allows inc/rt-popup.php d XSS. |
| CVE-2020-9368 | HIGH | 7.5 | 2.0% | Nov 2, 2020 | The Module Olea Gift On Order module through 5.0.8 for PrestaShop enables an unauthenticated user to read arbitrary file... |
| CVE-2020-8236 | MEDIUM | 6.8 | 0.6% | Nov 2, 2020 | A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two ... |
| CVE-2020-8183 | HIGH | 7.5 | 1.9% | Nov 2, 2020 | A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initi... |
| CVE-2020-8173 | LOW | 2.2 | 0.4% | Nov 2, 2020 | A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter ... |
| CVE-2020-6014 | MEDIUM | 6.5 | 0.4% | Nov 2, 2020 | Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83... |
| CVE-2020-5658 | HIGH | 7.5 | 2.9% | Nov 2, 2020 | Resource Management Errors vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 Et... |
| CVE-2020-5657 | MEDIUM | 6.5 | 1.1% | Nov 2, 2020 | Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function incl... |
| CVE-2020-5656 | CRITICAL | 9.8 | 2.9% | Nov 2, 2020 | Improper access control vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 Ether... |
| CVE-2020-5655 | HIGH | 7.5 | 2.9% | Nov 2, 2020 | NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 Eth... |
| CVE-2020-5654 | HIGH | 7.5 | 2.7% | Nov 2, 2020 | Session fixation vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP ... |
| CVE-2020-5653 | CRITICAL | 9.8 | 3.2% | Nov 2, 2020 | Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP N... |
| CVE-2020-5652 | HIGH | 7.5 | 3.5% | Nov 2, 2020 | Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 ... |
| CVE-2020-28046 | HIGH | 7.8 | 0.5% | Nov 2, 2020 | An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal ... |
| CVE-2020-28045 | HIGH | 7.8 | 0.4% | Nov 2, 2020 | An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and ... |
| CVE-2020-28044 | MEDIUM | 6.8 | 0.3% | Nov 2, 2020 | An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in manage... |
| CVE-2020-28043 | HIGH | 7.5 | 1.3% | Nov 2, 2020 | MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. |
| CVE-2020-28042 | MEDIUM | 5.3 | 2.3% | Nov 2, 2020 | ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken functio... |
| CVE-2020-28041 | MEDIUM | 6.5 | 2.0% | Nov 2, 2020 | The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate wi... |
| CVE-2020-28040 | MEDIUM | 4.3 | 1.1% | Nov 2, 2020 | WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. |
| CVE-2020-28039 | CRITICAL | 9.1 | 4.1% | Nov 2, 2020 | is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not p... |
| CVE-2020-28038 | MEDIUM | 6.1 | 2.6% | Nov 2, 2020 | WordPress before 5.5.2 allows stored XSS via post slugs. |
| CVE-2020-28037 | CRITICAL | 9.8 | 7.7% | Nov 2, 2020 | is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is alre... |
| CVE-2020-28036 | CRITICAL | 9.8 | 5.2% | Nov 2, 2020 | wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to... |
| CVE-2020-28035 | CRITICAL | 9.8 | 4.2% | Nov 2, 2020 | WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now