2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26134 | MEDIUM | 6.1 | 1.1% | Oct 2, 2020 | Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode. |
| CVE-2020-26124 | HIGH | 8.8 | 67.2% | Oct 2, 2020 | openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield PO... |
| CVE-2020-25741 | LOW | 3.2 | 0.4% | Oct 2, 2020 | fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the curren... |
| CVE-2020-24698 | CRITICAL | 9.8 | 3.0% | Oct 2, 2020 | An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, u... |
| CVE-2020-24697 | HIGH | 7.5 | 4.4% | Oct 2, 2020 | An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, u... |
| CVE-2020-24696 | HIGH | 8.1 | 1.3% | Oct 2, 2020 | An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, u... |
| CVE-2020-17482 | MEDIUM | 4.3 | 2.6% | Oct 2, 2020 | An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to inser... |
| CVE-2020-17382 | HIGH | 7.8 | 2.1% | Oct 2, 2020 | The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054). |
| CVE-2020-14294 | MEDIUM | 6.1 | 1.2% | Oct 2, 2020 | An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when re... |
| CVE-2020-14293 | HIGH | 7.5 | 5.3% | Oct 2, 2020 | conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacter... |
| CVE-2020-13168 | MEDIUM | 6.1 | 1.0% | Oct 2, 2020 | SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter. |
| CVE-2020-12127 | HIGH | 7.5 | 6.4% | Oct 2, 2020 | An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030... |
| CVE-2020-12126 | CRITICAL | 9.8 | 1.3% | Oct 2, 2020 | Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow... |
| CVE-2020-12125 | CRITICAL | 9.8 | 3.6% | Oct 2, 2020 | A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.19040... |
| CVE-2020-12124 | CRITICAL | 9.8 | 75.8% | Oct 2, 2020 | A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.1... |
| CVE-2020-12123 | HIGH | 8.1 | 0.4% | Oct 2, 2020 | CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely ... |
| CVE-2020-26540 | HIGH | 7.5 | 0.7% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mech... |
| CVE-2020-26539 | CRITICAL | 9.8 | 2.1% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V... |
| CVE-2020-26538 | HIGH | 7.8 | 0.5% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a ... |
| CVE-2020-26537 | CRITICAL | 9.8 | 1.1% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outp... |
| CVE-2020-26536 | MEDIUM | 5.5 | 0.9% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PD... |
| CVE-2020-26535 | CRITICAL | 9.8 | 1.7% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storag... |
| CVE-2020-26534 | CRITICAL | 9.8 | 2.3% | Oct 2, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Fie... |
| CVE-2020-26524 | MEDIUM | 5.3 | 1.4% | Oct 2, 2020 | CodeLathe FileCloud before 20.2.0.11915 allows username enumeration. |
| CVE-2020-26523 | MEDIUM | 6.1 | 0.7% | Oct 2, 2020 | Froala Editor before 3.2.2 allows XSS via pasted content. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now