2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19450 | HIGH | 7.5 | 1.1% | Sep 25, 2020 | SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, get... |
| CVE-2020-5930 | HIGH | 7.5 | 1.1% | Sep 25, 2020 | In BIG-IP 15.0.0-15.1.0.4, 14.1.0-14.1.2.7, 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 and BIG-IQ 5.2.0-7.1.0... |
| CVE-2020-5929 | MEDIUM | 5.9 | 1.2% | Sep 25, 2020 | In versions 13.0.0-13.0.0 HF2, 12.1.0-12.1.2 HF1, and 11.6.1-11.6.2, BIG-IP platforms with Cavium Nitrox SSL hardware ac... |
| CVE-2020-25131 | MEDIUM | 6.1 | 0.8% | Sep 25, 2020 | An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scr... |
| CVE-2020-25130 | MEDIUM | 6.5 | 1.0% | Sep 25, 2020 | An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection ... |
| CVE-2020-15374 | CRITICAL | 9.8 | 1.2% | Sep 25, 2020 | Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instan... |
| CVE-2020-15373 | CRITICAL | 9.8 | 2.4% | Sep 25, 2020 | Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 ver... |
| CVE-2020-15372 | MEDIUM | 5.5 | 0.3% | Sep 25, 2020 | A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v... |
| CVE-2020-15371 | CRITICAL | 9.8 | 1.3% | Sep 25, 2020 | Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code inject... |
| CVE-2020-15370 | MEDIUM | 6.5 | 1.0% | Sep 25, 2020 | Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user... |
| CVE-2020-15369 | HIGH | 8.8 | 1.0% | Sep 25, 2020 | Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfusca... |
| CVE-2020-13995 | CRITICAL | 9.8 | 2.7% | Sep 25, 2020 | U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow i... |
| CVE-2020-7735 | MEDIUM | 6.6 | 2.4% | Sep 25, 2020 | The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option. |
| CVE-2020-15521 | MEDIUM | 6.1 | 1.7% | Sep 25, 2020 | Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripti... |
| CVE-2020-15394 | CRITICAL | 9.8 | 7.9% | Sep 25, 2020 | The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a ... |
| CVE-2020-26115 | MEDIUM | 6.1 | 0.6% | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574). |
| CVE-2020-26114 | MEDIUM | 6.1 | 0.6% | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573). |
| CVE-2020-26113 | MEDIUM | 6.1 | 0.6% | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569). |
| CVE-2020-26112 | HIGH | 7.5 | 0.9% | Sep 25, 2020 | The email quota cache in cPanel before 90.0.10 allows overwriting of files. |
| CVE-2020-26111 | MEDIUM | 6.1 | 0.6% | Sep 25, 2020 | cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566). |
| CVE-2020-26110 | MEDIUM | 6.1 | 0.8% | Sep 25, 2020 | cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564). |
| CVE-2020-26109 | HIGH | 7.5 | 1.2% | Sep 25, 2020 | cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557). |
| CVE-2020-26108 | CRITICAL | 9.8 | 2.5% | Sep 25, 2020 | cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488). |
| CVE-2020-26107 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561). |
| CVE-2020-26106 | HIGH | 7.5 | 1.3% | Sep 25, 2020 | cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558). |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now