2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25987 | HIGH | 7.5 | 1.6% | Oct 6, 2020 | MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is b... |
| CVE-2020-25986 | MEDIUM | 6.5 | 0.6% | Oct 6, 2020 | A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user. |
| CVE-2020-25613 | HIGH | 7.5 | 3.8% | Oct 6, 2020 | An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP serv... |
| CVE-2020-24215 | CRITICAL | 9.8 | 19.0% | Oct 6, 2020 | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use har... |
| CVE-2020-24214 | CRITICAL | 9.8 | 35.4% | Oct 6, 2020 | An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a ... |
| CVE-2020-23832 | MEDIUM | 6.1 | 2.1% | Oct 6, 2020 | A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System... |
| CVE-2020-5634 | HIGH | 8.8 | 0.6% | Oct 6, 2020 | ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-17... |
| CVE-2020-5632 | HIGH | 7.8 | 0.4% | Oct 6, 2020 | InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revisi... |
| CVE-2020-5631 | MEDIUM | 6.1 | 1.0% | Oct 6, 2020 | Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arb... |
| CVE-2020-26572 | MEDIUM | 5.5 | 0.4% | Oct 6, 2020 | The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher. |
| CVE-2020-26571 | MEDIUM | 5.5 | 0.4% | Oct 6, 2020 | The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu... |
| CVE-2020-26570 | MEDIUM | 5.5 | 0.4% | Oct 6, 2020 | The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read... |
| CVE-2020-15237 | MEDIUM | 5.9 | 1.0% | Oct 5, 2020 | In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a tim... |
| CVE-2020-16226 | CRITICAL | 9.8 | 2.2% | Oct 5, 2020 | Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, whic... |
| CVE-2020-24231 | CRITICAL | 9.8 | 1.7% | Oct 5, 2020 | Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all... |
| CVE-2020-15235 | HIGH | 7.5 | 1.0% | Oct 5, 2020 | In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would norm... |
| CVE-2020-6875 | CRITICAL | 9.8 | 1.2% | Oct 5, 2020 | A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mech... |
| CVE-2020-26048 | HIGH | 8.8 | 1.8% | Oct 5, 2020 | The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within... |
| CVE-2020-15236 | HIGH | 7.5 | 1.7% | Oct 5, 2020 | In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with... |
| CVE-2020-8671 | MEDIUM | 5.5 | 0.3% | Oct 5, 2020 | Insufficient control flow management in BIOS firmware 8th, 9th Generation Intel(R) Core(TM) Processors and Intel(R) Cele... |
| CVE-2020-8235 | MEDIUM | 4.3 | 0.8% | Oct 5, 2020 | Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view a... |
| CVE-2020-8228 | MEDIUM | 5.3 | 1.9% | Oct 5, 2020 | A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount... |
| CVE-2020-8223 | MEDIUM | 6.5 | 1.5% | Oct 5, 2020 | A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher p... |
| CVE-2020-8182 | HIGH | 8 | 1.0% | Oct 5, 2020 | Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permiss... |
| CVE-2020-4493 | CRITICAL | 9.8 | 2.7% | Oct 5, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now