2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24654 | LOW | 3.3 | 1.5% | Sep 2, 2020 | In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as de... |
| CVE-2020-24553 | MEDIUM | 6.1 | 3.6% | Sep 2, 2020 | Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a ... |
| CVE-2020-24030 | CRITICAL | 9.8 | 2.7% | Sep 2, 2020 | ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access... |
| CVE-2020-24029 | CRITICAL | 9.8 | 2.0% | Sep 2, 2020 | Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can b... |
| CVE-2020-24028 | HIGH | 8.8 | 2.3% | Sep 2, 2020 | ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, passwor... |
| CVE-2020-23830 | HIGH | 7.1 | 0.5% | Sep 2, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 a... |
| CVE-2020-15811 | MEDIUM | 6.5 | 4.2% | Sep 2, 2020 | An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitt... |
| CVE-2020-15810 | MEDIUM | 6.5 | 2.5% | Sep 2, 2020 | An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggl... |
| CVE-2020-14209 | HIGH | 8.8 | 27.5% | Sep 2, 2020 | Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio... |
| CVE-2020-13802 | CRITICAL | 9.8 | 6.8% | Sep 2, 2020 | Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specificat... |
| CVE-2020-12621 | MEDIUM | 6.1 | 0.3% | Sep 2, 2020 | The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-c... |
| CVE-2020-25079 | HIGH | 8.8 | 52.7% | Sep 2, 2020 | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.c... |
| CVE-2020-25078 | HIGH | 7.5 | 97.9% | Sep 2, 2020 | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate... |
| CVE-2020-16150 | MEDIUM | 5.5 | 0.4% | Sep 2, 2020 | A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23... |
| CVE-2020-24604 | MEDIUM | 6.1 | 1.2% | Sep 2, 2020 | A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows rem... |
| CVE-2020-24602 | MEDIUM | 6.1 | 1.0% | Sep 2, 2020 | Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute ar... |
| CVE-2020-24601 | MEDIUM | 6.1 | 0.6% | Sep 2, 2020 | In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious... |
| CVE-2020-17458 | MEDIUM | 5.4 | 0.6% | Sep 2, 2020 | A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field. |
| CVE-2020-16602 | HIGH | 8.1 | 6.0% | Sep 2, 2020 | Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra... |
| CVE-2020-24355 | CRITICAL | 9.8 | 2.2% | Sep 2, 2020 | Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insec... |
| CVE-2020-5622 | HIGH | 7.5 | 1.3% | Sep 2, 2020 | Shadankun Server Security Type (excluding normal blocking method types) Ver.1.5.3 and earlier allows remote attackers to... |
| CVE-2020-25073 | MEDIUM | 5.3 | 2.1% | Sep 2, 2020 | FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apa... |
| CVE-2020-8341 | LOW | 2.4 | 0.3% | Sep 1, 2020 | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient prot... |
| CVE-2020-8335 | MEDIUM | 6.8 | 0.3% | Sep 1, 2020 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS ... |
| CVE-2020-24955 | HIGH | 7.8 | 0.9% | Sep 1, 2020 | SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivilege... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now