2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-23837HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attacke...
CVE-2020-13387HIGH7.5Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.
CVE-2020-12824HIGH7.5Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.
CVE-2020-11805CRITICAL9.8Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
CVE-2020-17365HIGH7.8Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an aut...
CVE-2020-15843HIGH7.3ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folde...
CVE-2020-15162MEDIUM5.4In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attach...
CVE-2020-15160CRITICAL9.8PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog ...
CVE-2020-13991HIGH7.5vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.
CVE-2020-15161MEDIUM6.1In PrestaShop from version 1.6.0.4 and before version 1.7.6.8 an attacker is able to inject javascript while using the c...
CVE-2020-8348MEDIUM6.1A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1...
CVE-2020-8347MEDIUM6.1A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6....
CVE-2020-8344Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-8343Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-8333HIGH7.8A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStatio...
CVE-2020-8328Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-8325Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2020-15851CRITICAL9.8Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access une...
CVE-2020-15850HIGH7.8Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access t...
CVE-2020-19447HIGH7.5SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_file...
CVE-2020-15930MEDIUM6.1An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
CVE-2020-3560HIGH8.6A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial o...
CVE-2020-3559HIGH8.6A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an ...
CVE-2020-3552HIGH7.4A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthentic...
CVE-2020-3527HIGH8.6A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote atta...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now