2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25375 | MEDIUM | 5.4 | 0.7% | Sep 14, 2020 | Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name ... |
| CVE-2020-22158 | MEDIUM | 6.1 | 0.7% | Sep 14, 2020 | MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has... |
| CVE-2020-8817 | HIGH | 8.1 | 0.9% | Sep 14, 2020 | Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata. |
| CVE-2020-12789 | HIGH | 7.5 | 1.2% | Sep 14, 2020 | The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets. |
| CVE-2020-12788 | HIGH | 7.5 | 1.3% | Sep 14, 2020 | CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power anal... |
| CVE-2020-12787 | HIGH | 7.5 | 1.2% | Sep 14, 2020 | Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to appl... |
| CVE-2020-11684 | CRITICAL | 9.1 | 1.1% | Sep 14, 2020 | AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control ... |
| CVE-2020-11683 | MEDIUM | 6.8 | 0.5% | Sep 14, 2020 | A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical acces... |
| CVE-2020-25540 | HIGH | 7.5 | 75.9% | Sep 14, 2020 | ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on ... |
| CVE-2020-24660 | CRITICAL | 9.8 | 2.3% | Sep 14, 2020 | An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access cont... |
| CVE-2020-7807 | MEDIUM | 5.5 | 0.2% | Sep 14, 2020 | A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTR... |
| CVE-2020-21733 | MEDIUM | 6.1 | 1.0% | Sep 14, 2020 | Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp. |
| CVE-2020-21732 | MEDIUM | 6.1 | 0.9% | Sep 14, 2020 | Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code t... |
| CVE-2020-21731 | MEDIUM | 6.1 | 0.9% | Sep 14, 2020 | Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?use... |
| CVE-2020-25291 | HIGH | 7.8 | 1.6% | Sep 13, 2020 | GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in ... |
| CVE-2020-25289 | MEDIUM | 5.5 | 0.4% | Sep 13, 2020 | The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Man... |
| CVE-2020-25287 | HIGH | 7.2 | 2.7% | Sep 13, 2020 | Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any fil... |
| CVE-2020-25286 | MEDIUM | 5.3 | 1.9% | Sep 13, 2020 | In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in t... |
| CVE-2020-25285 | MEDIUM | 6.4 | 0.3% | Sep 13, 2020 | A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local... |
| CVE-2020-25284 | MEDIUM | 4.1 | 0.3% | Sep 13, 2020 | The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking... |
| CVE-2020-25283 | CRITICAL | 9.8 | 0.5% | Sep 11, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers... |
| CVE-2020-25282 | CRITICAL | 9.8 | 0.4% | Sep 11, 2020 | An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Inte... |
| CVE-2020-25281 | HIGH | 7.5 | 0.3% | Sep 11, 2020 | An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sen... |
| CVE-2020-25280 | MEDIUM | 6.8 | 0.2% | Sep 11, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated ... |
| CVE-2020-25279 | CRITICAL | 9.8 | 0.7% | Sep 11, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseb... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now