2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15771 | HIGH | 7.5 | 1.0% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission ... |
| CVE-2020-15770 | MEDIUM | 5.5 | 0.3% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local... |
| CVE-2020-15769 | MEDIUM | 6.1 | 0.7% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL. |
| CVE-2020-15768 | HIGH | 7.5 | 1.7% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestr... |
| CVE-2020-15767 | MEDIUM | 5.3 | 0.5% | Sep 18, 2020 | An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not... |
| CVE-2020-5629 | MEDIUM | 6.5 | 1.0% | Sep 18, 2020 | UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website ... |
| CVE-2020-5628 | MEDIUM | 6.5 | 1.0% | Sep 18, 2020 | UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website ... |
| CVE-2020-5606 | MEDIUM | 6.1 | 0.8% | Sep 18, 2020 | Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary scr... |
| CVE-2020-5605 | MEDIUM | 4.3 | 1.1% | Sep 18, 2020 | Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive informati... |
| CVE-2020-25756 | CRITICAL | 9.8 | 1.6% | Sep 18, 2020 | A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of boun... |
| CVE-2020-25751 | HIGH | 8.8 | 1.8% | Sep 18, 2020 | The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=c... |
| CVE-2020-25750 | HIGH | 7.5 | 1.1% | Sep 18, 2020 | An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is ... |
| CVE-2020-25744 | HIGH | 8.1 | 1.4% | Sep 18, 2020 | SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could ... |
| CVE-2020-25735 | MEDIUM | 6.1 | 1.4% | Sep 18, 2020 | webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement... |
| CVE-2020-25734 | MEDIUM | 5.3 | 2.1% | Sep 18, 2020 | webTareas through 2.1 allows files/Default/ Directory Listing. |
| CVE-2020-25733 | HIGH | 7.5 | 2.1% | Sep 18, 2020 | webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types. |
| CVE-2020-15187 | MEDIUM | 4.7 | 1.4% | Sep 17, 2020 | In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one alw... |
| CVE-2020-15186 | LOW | 2.7 | 1.0% | Sep 17, 2020 | In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin autho... |
| CVE-2020-15185 | LOW | 2.7 | 0.9% | Sep 17, 2020 | In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one... |
| CVE-2020-15184 | LOW | 2.7 | 1.0% | Sep 17, 2020 | In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sa... |
| CVE-2020-0426 | MEDIUM | 5.5 | 0.1% | Sep 17, 2020 | In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informati... |
| CVE-2020-0425 | MEDIUM | 5.5 | 0.1% | Sep 17, 2020 | There is a possible way to view notifications even when the "Lockdown" feature is on. This could lead to local informati... |
| CVE-2020-0406 | HIGH | 7.8 | 0.4% | Sep 17, 2020 | In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalati... |
| CVE-2020-0375 | HIGH | 7.8 | 0.2% | Sep 17, 2020 | In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalati... |
| CVE-2020-0374 | HIGH | 7.8 | 0.2% | Sep 17, 2020 | In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of pri... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now