2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25593 | MEDIUM | 6.7 | 0.3% | Jul 15, 2021 | Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder per... |
| CVE-2020-12730 | MEDIUM | 5.3 | 0.2% | Jul 15, 2021 | MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery. |
| CVE-2020-12729 | MEDIUM | 4.6 | 0.3% | Jul 15, 2021 | MagicMotion Flamingo 2 has a lack of access control for reading from device descriptors. |
| CVE-2020-18151 | MEDIUM | 6.5 | 0.5% | Jul 14, 2021 | Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account. |
| CVE-2020-18145 | MEDIUM | 6.1 | 0.8% | Jul 14, 2021 | Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php. |
| CVE-2020-29146 | MEDIUM | 6.1 | 0.7% | Jul 14, 2021 | A cross site scripting (XSS) vulnerability in index.php of Wayang-CMS v1.0 allows attackers to execute arbitrary web scr... |
| CVE-2020-27379 | MEDIUM | 6.5 | 0.5% | Jul 14, 2021 | Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF ... |
| CVE-2020-25444 | MEDIUM | 5.4 | 0.6% | Jul 14, 2021 | Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About... |
| CVE-2020-20231 | MEDIUM | 6.5 | 2.0% | Jul 14, 2021 | Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet p... |
| CVE-2020-19722 | MEDIUM | 6.5 | 1.0% | Jul 13, 2021 | An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a direct copy to NULL pointer deref... |
| CVE-2020-19721 | MEDIUM | 6.5 | 1.2% | Jul 13, 2021 | A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while runn... |
| CVE-2020-19720 | MEDIUM | 6.5 | 1.0% | Jul 13, 2021 | An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, lea... |
| CVE-2020-19719 | MEDIUM | 6.5 | 5.7% | Jul 13, 2021 | A buffer overflow vulnerability in Ap4ElstAtom.cpp of Bento 1.5.1-628 leads to a denial of service (DOS). |
| CVE-2020-19718 | MEDIUM | 6.5 | 1.0% | Jul 13, 2021 | An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading... |
| CVE-2020-19717 | MEDIUM | 6.5 | 1.0% | Jul 13, 2021 | An unhandled memory allocation failure in Core/Ap48bdlAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, lea... |
| CVE-2020-19716 | MEDIUM | 6.5 | 1.1% | Jul 13, 2021 | A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS)... |
| CVE-2020-20252 | MEDIUM | 6.5 | 1.6% | Jul 13, 2021 | Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat pro... |
| CVE-2020-20250 | MEDIUM | 6.5 | 1.7% | Jul 13, 2021 | Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat pro... |
| CVE-2020-26153 | MEDIUM | 6.1 | 3.8% | Jul 13, 2021 | A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/... |
| CVE-2020-19037 | MEDIUM | 5.3 | 0.9% | Jul 12, 2021 | Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted... |
| CVE-2020-18982 | MEDIUM | 5.4 | 0.6% | Jul 12, 2021 | Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl. |
| CVE-2020-19204 | MEDIUM | 5.4 | 0.7% | Jul 12, 2021 | An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - C... |
| CVE-2020-19203 | MEDIUM | 5.4 | 1.1% | Jul 12, 2021 | An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a compone... |
| CVE-2020-19201 | MEDIUM | 5.4 | 3.5% | Jul 12, 2021 | A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software ... |
| CVE-2020-18979 | MEDIUM | 6.1 | 0.7% | Jul 12, 2021 | Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now