2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24159 | HIGH | 7.8 | 0.4% | Sep 3, 2020 | NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissi... |
| CVE-2020-24158 | HIGH | 7.8 | 0.3% | Sep 3, 2020 | 360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute maliciou... |
| CVE-2020-23814 | MEDIUM | 6.1 | 1.2% | Sep 3, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web scr... |
| CVE-2020-23811 | HIGH | 7.5 | 1.2% | Sep 3, 2020 | xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.jav... |
| CVE-2020-25105 | CRITICAL | 9.8 | 1.1% | Sep 3, 2020 | eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilit... |
| CVE-2020-25104 | MEDIUM | 5.4 | 0.6% | Sep 3, 2020 | eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For exam... |
| CVE-2020-25068 | HIGH | 7.5 | 3.9% | Sep 3, 2020 | Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unau... |
| CVE-2020-25042 | HIGH | 7.2 | 18.1% | Sep 3, 2020 | An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authentic... |
| CVE-2020-24948 | HIGH | 7.2 | 13.1% | Sep 3, 2020 | The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimat... |
| CVE-2020-24863 | MEDIUM | 5.5 | 0.5% | Sep 3, 2020 | A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 th... |
| CVE-2020-24385 | MEDIUM | 5.5 | 0.4% | Sep 3, 2020 | In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in th... |
| CVE-2020-16149 | — | — | — | Sep 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its request... |
| CVE-2020-13972 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the ... |
| CVE-2020-7382 | MEDIUM | 6.5 | 0.3% | Sep 3, 2020 | Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the loc... |
| CVE-2020-7381 | HIGH | 7.8 | 0.7% | Sep 3, 2020 | In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in t... |
| CVE-2020-4638 | HIGH | 7.2 | 1.7% | Sep 3, 2020 | IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API... |
| CVE-2020-4337 | MEDIUM | 6.5 | 1.1% | Sep 3, 2020 | IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server... |
| CVE-2020-24949 | HIGH | 8.8 | 67.3% | Sep 3, 2020 | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr... |
| CVE-2020-12058 | MEDIUM | 6.1 | 1.0% | Sep 3, 2020 | Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary Ja... |
| CVE-2020-7729 | HIGH | 7.1 | 2.4% | Sep 3, 2020 | The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load(... |
| CVE-2020-25093 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop... |
| CVE-2020-25092 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/cl... |
| CVE-2020-25091 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php. |
| CVE-2020-25090 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php. |
| CVE-2020-25089 | MEDIUM | 6.1 | 0.7% | Sep 3, 2020 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now