2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15386 | MEDIUM | 5.3 | 1.0% | Jun 9, 2021 | Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scan... |
| CVE-2020-15385 | MEDIUM | 5.4 | 0.5% | Jun 9, 2021 | Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permiss... |
| CVE-2020-15384 | MEDIUM | 5.3 | 0.5% | Jun 9, 2021 | Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of interna... |
| CVE-2020-15378 | MEDIUM | 5.3 | 0.8% | Jun 9, 2021 | The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container po... |
| CVE-2020-11266 | MEDIUM | 6.5 | 0.2% | Jun 9, 2021 | Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdrag... |
| CVE-2020-11265 | MEDIUM | 5.5 | 0.2% | Jun 9, 2021 | Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrast... |
| CVE-2020-11160 | MEDIUM | 6.7 | 0.1% | Jun 9, 2021 | Resource leakage issue during dci client registration due to reference count is not decremented if dci client registrati... |
| CVE-2020-26136 | MEDIUM | 6.5 | 1.2% | Jun 8, 2021 | In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authenticat... |
| CVE-2020-28713 | MEDIUM | 6.5 | 1.4% | Jun 8, 2021 | Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote user... |
| CVE-2020-26138 | MEDIUM | 5.3 | 1.3% | Jun 8, 2021 | In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation. |
| CVE-2020-25817 | MEDIUM | 4.8 | 0.8% | Jun 8, 2021 | SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML ... |
| CVE-2020-26517 | MEDIUM | 4.8 | 0.5% | Jun 8, 2021 | A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to per... |
| CVE-2020-1750 | MEDIUM | 6.5 | 0.9% | Jun 7, 2021 | A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container co... |
| CVE-2020-1690 | MEDIUM | 6.5 | 0.2% | Jun 7, 2021 | An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root... |
| CVE-2020-18268 | MEDIUM | 6.1 | 2.7% | Jun 7, 2021 | Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect"... |
| CVE-2020-1719 | MEDIUM | 5.4 | 0.6% | Jun 7, 2021 | A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Se... |
| CVE-2020-5008 | MEDIUM | 5.3 | 0.9% | Jun 7, 2021 | IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET r... |
| CVE-2020-36384 | MEDIUM | 6.1 | 0.8% | Jun 7, 2021 | PageLayer before 1.3.5 allows reflected XSS via color settings. |
| CVE-2020-36383 | MEDIUM | 6.1 | 0.8% | Jun 7, 2021 | PageLayer before 1.3.5 allows reflected XSS via the font-size parameter. |
| CVE-2020-26885 | MEDIUM | 6.1 | 1.1% | Jun 7, 2021 | An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an ... |
| CVE-2020-36142 | MEDIUM | 6.5 | 1.4% | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. |
| CVE-2020-36140 | MEDIUM | 6.5 | 0.6% | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of '... |
| CVE-2020-36139 | MEDIUM | 5.4 | 0.5% | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'file... |
| CVE-2020-15077 | MEDIUM | 5.3 | 1.2% | Jun 4, 2021 | OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control c... |
| CVE-2020-36007 | MEDIUM | 6.1 | 0.9% | Jun 3, 2021 | AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now