2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7521CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC E...
CVE-2020-20628MEDIUM6.1controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
CVE-2020-24699MEDIUM6.1The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
CVE-2020-24363HIGH8.8TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP...
CVE-2020-20627MEDIUM5.3The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauth...
CVE-2020-20626MEDIUM5.4lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.
CVE-2020-20625HIGH7.5Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated S...
CVE-2020-17465MEDIUM6.1Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vuln...
CVE-2020-15687HIGH7.5Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious ...
CVE-2020-13828MEDIUM5.4Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authen...
CVE-2020-13472MEDIUM4.6The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the...
CVE-2020-13471MEDIUM6.8Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a spec...
CVE-2020-13470MEDIUM4.6Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible b...
CVE-2020-13469MEDIUM4.6The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via th...
CVE-2020-13468MEDIUM6.8Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection i...
CVE-2020-13467MEDIUM4.6The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attacker...
CVE-2020-13466MEDIUM6.8STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power g...
CVE-2020-13465MEDIUM6.8The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execut...
CVE-2020-13464MEDIUM4.2The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attacker...
CVE-2020-13463MEDIUM4.6The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firm...
CVE-2020-5419MEDIUM6.7RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allow...
CVE-2020-24786CRITICAL9.8An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number ...
CVE-2020-13655MEDIUM6.1An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is s...
CVE-2020-13595MEDIUM6.5The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) return...
CVE-2020-13594MEDIUM6.5The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does n...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now