2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17385 | HIGH | 7.5 | 1.6% | Aug 25, 2020 | Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to lau... |
| CVE-2020-17384 | HIGH | 7.2 | 1.9% | Aug 25, 2020 | Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system adminis... |
| CVE-2020-5620 | MEDIUM | 5.4 | 0.6% | Aug 25, 2020 | Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary s... |
| CVE-2020-5619 | MEDIUM | 5.4 | 0.7% | Aug 25, 2020 | Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary s... |
| CVE-2020-5541 | MEDIUM | 6.1 | 1.4% | Aug 25, 2020 | Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary site... |
| CVE-2020-5540 | MEDIUM | 6.1 | 1.5% | Aug 25, 2020 | Cross-site scripting vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to inject arbitrary script o... |
| CVE-2020-24613 | MEDIUM | 6.8 | 0.9% | Aug 24, 2020 | wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in t... |
| CVE-2020-24612 | MEDIUM | 4.7 | 0.3% | Aug 24, 2020 | An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config... |
| CVE-2020-24572 | HIGH | 8.8 | 6.8% | Aug 24, 2020 | An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misco... |
| CVE-2020-7377 | HIGH | 7.5 | 1.1% | Aug 24, 2020 | The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path tr... |
| CVE-2020-7376 | CRITICAL | 9.8 | 1.1% | Aug 24, 2020 | The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability... |
| CVE-2020-6637 | CRITICAL | 9.8 | 20.1% | Aug 24, 2020 | openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php. |
| CVE-2020-24364 | HIGH | 8.8 | 2.6% | Aug 24, 2020 | MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meetin... |
| CVE-2020-7705 | HIGH | 8.1 | 1.2% | Aug 24, 2020 | This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality ... |
| CVE-2020-24606 | HIGH | 7.5 | 5.2% | Aug 24, 2020 | Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU... |
| CVE-2020-10775 | MEDIUM | 5.3 | 1.8% | Aug 24, 2020 | An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to r... |
| CVE-2020-4598 | MEDIUM | 6.1 | 0.8% | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect a... |
| CVE-2020-4593 | MEDIUM | 4.4 | 0.3% | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. I... |
| CVE-2020-4587 | HIGH | 7.8 | 0.3% | Aug 24, 2020 | IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, 6.0.0, and 6.1.0 is vulnerable to a stack based buffer ovreflow, caus... |
| CVE-2020-4383 | MEDIUM | 6.5 | 1.1% | Aug 24, 2020 | IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denia... |
| CVE-2020-4382 | MEDIUM | 5.5 | 0.3% | Aug 24, 2020 | IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denia... |
| CVE-2020-4170 | MEDIUM | 4.3 | 0.4% | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execut... |
| CVE-2020-4165 | MEDIUM | 5.4 | 0.6% | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persu... |
| CVE-2020-14044 | HIGH | 7.2 | 3.2% | Aug 24, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 ... |
| CVE-2020-14043 | HIGH | 8.8 | 1.5% | Aug 24, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now