2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5383 | MEDIUM | 5.3 | 1.0% | Aug 27, 2020 | Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability... |
| CVE-2020-24717 | HIGH | 7.8 | 0.5% | Aug 27, 2020 | OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by ... |
| CVE-2020-24716 | HIGH | 7.8 | 0.5% | Aug 27, 2020 | OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories. |
| CVE-2020-24203 | CRITICAL | 9.8 | 3.7% | Aug 27, 2020 | Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects Worl... |
| CVE-2020-24202 | CRITICAL | 9.8 | 2.9% | Aug 27, 2020 | File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regul... |
| CVE-2020-24196 | HIGH | 7.2 | 2.7% | Aug 27, 2020 | An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote... |
| CVE-2020-3517 | HIGH | 8.6 | 1.4% | Aug 27, 2020 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an un... |
| CVE-2020-3504 | LOW | 3.3 | 0.3% | Aug 27, 2020 | A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, loc... |
| CVE-2020-3454 | HIGH | 7.2 | 2.6% | Aug 27, 2020 | A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject... |
| CVE-2020-3415 | HIGH | 8.8 | 0.8% | Aug 27, 2020 | A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthenticated, adjacent att... |
| CVE-2020-3398 | HIGH | 8.6 | 1.8% | Aug 27, 2020 | A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could a... |
| CVE-2020-3397 | HIGH | 8.6 | 1.8% | Aug 27, 2020 | A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could a... |
| CVE-2020-3394 | HIGH | 7.8 | 0.3% | Aug 27, 2020 | A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in... |
| CVE-2020-3338 | HIGH | 7.5 | 1.8% | Aug 27, 2020 | A vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) of Cisco NX-OS Software cou... |
| CVE-2020-24706 | MEDIUM | 6.1 | 0.8% | Aug 27, 2020 | An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through... |
| CVE-2020-24705 | HIGH | 8.8 | 1.1% | Aug 27, 2020 | An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an att... |
| CVE-2020-24704 | MEDIUM | 6.1 | 0.7% | Aug 27, 2020 | An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager 2.2.0, ... |
| CVE-2020-24703 | HIGH | 8.8 | 1.1% | Aug 27, 2020 | An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an att... |
| CVE-2020-24390 | MEDIUM | 6.1 | 1.0% | Aug 27, 2020 | eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might a... |
| CVE-2020-23576 | MEDIUM | 5.4 | 0.5% | Aug 27, 2020 | Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab. |
| CVE-2020-16142 | LOW | 3.5 | 0.8% | Aug 27, 2020 | On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string ... |
| CVE-2020-14415 | LOW | 3.3 | 0.5% | Aug 27, 2020 | oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position. |
| CVE-2020-23984 | MEDIUM | 5.4 | 0.6% | Aug 27, 2020 | Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-ta... |
| CVE-2020-23983 | MEDIUM | 5.4 | 0.6% | Aug 27, 2020 | Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags. |
| CVE-2020-23982 | MEDIUM | 6.1 | 0.5% | Aug 27, 2020 | DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php' |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now