2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-23837 | HIGH | 8.8 | 0.8% | Sep 25, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attacke... |
| CVE-2020-13387 | HIGH | 7.5 | 1.1% | Sep 25, 2020 | Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323. |
| CVE-2020-12824 | HIGH | 7.5 | 1.1% | Sep 25, 2020 | Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP. |
| CVE-2020-11805 | CRITICAL | 9.8 | 1.4% | Sep 25, 2020 | Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN. |
| CVE-2020-17365 | HIGH | 7.8 | 0.4% | Sep 24, 2020 | Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an aut... |
| CVE-2020-15843 | HIGH | 7.3 | 0.4% | Sep 24, 2020 | ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folde... |
| CVE-2020-15162 | MEDIUM | 5.4 | 0.8% | Sep 24, 2020 | In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attach... |
| CVE-2020-15160 | CRITICAL | 9.8 | 10.8% | Sep 24, 2020 | PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog ... |
| CVE-2020-13991 | HIGH | 7.5 | 2.5% | Sep 24, 2020 | vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register. |
| CVE-2020-15161 | MEDIUM | 6.1 | 0.9% | Sep 24, 2020 | In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the c... |
| CVE-2020-8348 | MEDIUM | 6.1 | 1.0% | Sep 24, 2020 | A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1... |
| CVE-2020-8347 | MEDIUM | 6.1 | 1.1% | Sep 24, 2020 | A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.... |
| CVE-2020-8344 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-8343 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-8333 | HIGH | 7.8 | 0.3% | Sep 24, 2020 | A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStatio... |
| CVE-2020-8328 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-8325 | — | — | — | Sep 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-15851 | CRITICAL | 9.8 | 1.5% | Sep 24, 2020 | Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access une... |
| CVE-2020-15850 | HIGH | 7.8 | 0.5% | Sep 24, 2020 | Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access t... |
| CVE-2020-19447 | HIGH | 7.5 | 1.1% | Sep 24, 2020 | SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_file... |
| CVE-2020-15930 | MEDIUM | 6.1 | 4.4% | Sep 24, 2020 | An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. |
| CVE-2020-3560 | HIGH | 8.6 | 1.4% | Sep 24, 2020 | A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial o... |
| CVE-2020-3559 | HIGH | 8.6 | 1.4% | Sep 24, 2020 | A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an ... |
| CVE-2020-3552 | HIGH | 7.4 | 0.5% | Sep 24, 2020 | A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthentic... |
| CVE-2020-3527 | HIGH | 8.6 | 1.4% | Sep 24, 2020 | A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote atta... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now