2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15276 | HIGH | 8.7 | 1.0% | Oct 30, 2020 | baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a ... |
| CVE-2020-15273 | HIGH | 8.1 | 1.0% | Oct 30, 2020 | baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit fe... |
| CVE-2020-15277 | HIGH | 7.2 | 2.2% | Oct 30, 2020 | baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system... |
| CVE-2020-7373 | CRITICAL | 9.8 | 46.0% | Oct 30, 2020 | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe... |
| CVE-2020-4588 | HIGH | 7.8 | 1.3% | Oct 30, 2020 | IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting... |
| CVE-2020-4584 | HIGH | 7.5 | 1.0% | Oct 30, 2020 | IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error messag... |
| CVE-2020-7760 | HIGH | 7.5 | 5.2% | Oct 30, 2020 | This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The... |
| CVE-2020-7759 | HIGH | 7.2 | 1.3% | Oct 30, 2020 | The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functiona... |
| CVE-2020-27015 | MEDIUM | 4.4 | 0.9% | Oct 30, 2020 | Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exp... |
| CVE-2020-27014 | MEDIUM | 6.4 | 0.3% | Oct 30, 2020 | Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Block... |
| CVE-2020-27885 | MEDIUM | 6.1 | 0.9% | Oct 29, 2020 | Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability t... |
| CVE-2020-26205 | MEDIUM | 5.4 | 0.7% | Oct 29, 2020 | Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal throug... |
| CVE-2020-25646 | HIGH | 7.5 | 1.4% | Oct 29, 2020 | A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This direc... |
| CVE-2020-14323 | MEDIUM | 5.5 | 0.6% | Oct 29, 2020 | A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and befor... |
| CVE-2020-27887 | HIGH | 8.8 | 1.7% | Oct 29, 2020 | An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could a... |
| CVE-2020-27886 | CRITICAL | 9.8 | 1.7% | Oct 29, 2020 | An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injectio... |
| CVE-2020-27998 | CRITICAL | 9.8 | 2.3% | Oct 29, 2020 | An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (fo... |
| CVE-2020-27996 | HIGH | 8.8 | 2.1% | Oct 29, 2020 | An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttri... |
| CVE-2020-27747 | MEDIUM | 6.8 | 1.1% | Oct 29, 2020 | An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a... |
| CVE-2020-27995 | CRITICAL | 9.8 | 8.7% | Oct 29, 2020 | SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the se... |
| CVE-2020-27744 | CRITICAL | 9.8 | 5.9% | Oct 29, 2020 | An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with r... |
| CVE-2020-25780 | HIGH | 7.5 | 9.9% | Oct 29, 2020 | In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, D... |
| CVE-2020-5936 | HIGH | 7.5 | 1.1% | Oct 29, 2020 | On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel... |
| CVE-2020-5935 | MEDIUM | 5.9 | 0.8% | Oct 29, 2020 | On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.... |
| CVE-2020-5934 | MEDIUM | 6.5 | 0.4% | Oct 29, 2020 | On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now