2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3143 | HIGH | 7.2 | 8.5% | Sep 23, 2020 | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TeleP... |
| CVE-2020-3137 | MEDIUM | 6.1 | 0.8% | Sep 23, 2020 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthentic... |
| CVE-2020-3135 | HIGH | 8.8 | 0.5% | Sep 23, 2020 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unaut... |
| CVE-2020-3133 | HIGH | 7.5 | 1.4% | Sep 23, 2020 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a... |
| CVE-2020-3130 | MEDIUM | 6.5 | 1.8% | Sep 23, 2020 | A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker t... |
| CVE-2020-3124 | MEDIUM | 6.5 | 0.5% | Sep 23, 2020 | A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an un... |
| CVE-2020-3117 | MEDIUM | 4.7 | 0.9% | Sep 23, 2020 | A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security ... |
| CVE-2020-3116 | MEDIUM | 5.5 | 0.7% | Sep 23, 2020 | A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an a... |
| CVE-2020-25515 | HIGH | 7.8 | 0.5% | Sep 22, 2020 | Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<s... |
| CVE-2020-25514 | HIGH | 8.4 | 0.6% | Sep 22, 2020 | Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://... |
| CVE-2020-15839 | MEDIUM | 6.5 | 2.2% | Sep 22, 2020 | Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the siz... |
| CVE-2020-14031 | HIGH | 7.2 | 1.6% | Sep 22, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be u... |
| CVE-2020-14028 | HIGH | 7.2 | 1.9% | Sep 22, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Auto... |
| CVE-2020-14027 | MEDIUM | 5.3 | 0.8% | Sep 22, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arg... |
| CVE-2020-14026 | HIGH | 8.8 | 1.7% | Sep 22, 2020 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS ... |
| CVE-2020-14025 | HIGH | 8.8 | 0.5% | Sep 22, 2020 | Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a lin... |
| CVE-2020-14024 | MEDIUM | 6.1 | 0.7% | Sep 22, 2020 | Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) R... |
| CVE-2020-14023 | MEDIUM | 4.9 | 1.0% | Sep 22, 2020 | Ozeki NG SMS Gateway through 4.17.6 allows SSRF via SMS WCF or RSS To SMS. |
| CVE-2020-14022 | HIGH | 8.8 | 1.8% | Sep 22, 2020 | Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contac... |
| CVE-2020-25487 | HIGH | 7.8 | 0.6% | Sep 22, 2020 | PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php... |
| CVE-2020-24333 | MEDIUM | 6.5 | 0.8% | Sep 22, 2020 | A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rig... |
| CVE-2020-16202 | HIGH | 7.8 | 0.4% | Sep 22, 2020 | WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, whic... |
| CVE-2020-11856 | CRITICAL | 9.8 | 5.2% | Sep 22, 2020 | Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. Th... |
| CVE-2020-4622 | HIGH | 7.5 | 1.2% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it us... |
| CVE-2020-4621 | HIGH | 8.8 | 1.3% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now