2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28911 | MEDIUM | 6.5 | 2.7% | May 24, 2021 | Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwor... |
| CVE-2020-28903 | MEDIUM | 6.1 | 10.1% | May 24, 2021 | Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server t... |
| CVE-2020-26006 | MEDIUM | 6.1 | 0.7% | May 24, 2021 | Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php. |
| CVE-2020-25411 | MEDIUM | 6.5 | 0.7% | May 24, 2021 | Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing... |
| CVE-2020-25408 | MEDIUM | 6.5 | 0.8% | May 24, 2021 | A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows ... |
| CVE-2020-23766 | MEDIUM | 6.5 | 1.4% | May 21, 2021 | An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolut... |
| CVE-2020-27211 | MEDIUM | 5.7 | 0.3% | May 21, 2021 | Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The fl... |
| CVE-2020-27208 | MEDIUM | 6.8 | 0.3% | May 21, 2021 | The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.... |
| CVE-2020-21345 | MEDIUM | 6.1 | 0.8% | May 20, 2021 | Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a rem... |
| CVE-2020-21056 | MEDIUM | 4.3 | 1.0% | May 20, 2021 | Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via ... |
| CVE-2020-21055 | MEDIUM | 6.5 | 1.2% | May 20, 2021 | A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.vi... |
| CVE-2020-21054 | MEDIUM | 6.1 | 0.7% | May 20, 2021 | Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script... |
| CVE-2020-21053 | MEDIUM | 6.1 | 0.7% | May 20, 2021 | Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary we... |
| CVE-2020-24395 | MEDIUM | 6.8 | 0.2% | May 20, 2021 | The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical acces... |
| CVE-2020-15522 | MEDIUM | 5.9 | 1.5% | May 20, 2021 | Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 ha... |
| CVE-2020-4646 | MEDIUM | 4.3 | 0.7% | May 19, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5, 6.0.0.0 through 6.0.3.3, and 6.1.0.0 through 6.1.0... |
| CVE-2020-36365 | MEDIUM | 6.1 | 2.6% | May 19, 2021 | Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, ... |
| CVE-2020-20266 | MEDIUM | 6.5 | 2.1% | May 19, 2021 | Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x proces... |
| CVE-2020-20264 | MEDIUM | 6.5 | 2.1% | May 19, 2021 | Mikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated ... |
| CVE-2020-20246 | MEDIUM | 6.5 | 2.7% | May 18, 2021 | Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated r... |
| CVE-2020-20245 | MEDIUM | 6.5 | 2.7% | May 18, 2021 | Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remo... |
| CVE-2020-20227 | MEDIUM | 6.5 | 3.1% | May 18, 2021 | Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenti... |
| CVE-2020-20220 | MEDIUM | 6.5 | 2.7% | May 18, 2021 | Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An a... |
| CVE-2020-19924 | MEDIUM | 5.4 | 0.5% | May 18, 2021 | In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks. |
| CVE-2020-20237 | MEDIUM | 6.5 | 2.8% | May 18, 2021 | Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now