2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7301 | MEDIUM | 4.6 | 0.5% | Aug 12, 2020 | Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticat... |
| CVE-2020-7300 | MEDIUM | 6.3 | 0.6% | Aug 12, 2020 | Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authentic... |
| CVE-2020-17450 | MEDIUM | 6.1 | 0.8% | Aug 12, 2020 | PHP-Fusion 9.03 allows XSS on the preview page. |
| CVE-2020-17449 | MEDIUM | 5.4 | 0.5% | Aug 12, 2020 | PHP-Fusion 9.03 allows XSS via the error_log file. |
| CVE-2020-17362 | MEDIUM | 6.1 | 2.9% | Aug 12, 2020 | search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS. |
| CVE-2020-15868 | HIGH | 7.5 | 1.1% | Aug 12, 2020 | Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control. |
| CVE-2020-15596 | MEDIUM | 6.7 | 0.4% | Aug 12, 2020 | The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attacker... |
| CVE-2020-16186 | — | — | — | Aug 12, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2020-16139 | HIGH | 7.5 | 79.8% | Aug 12, 2020 | A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the de... |
| CVE-2020-16138 | HIGH | 7.5 | 21.4% | Aug 12, 2020 | A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remot... |
| CVE-2020-16137 | CRITICAL | 9.8 | 19.4% | Aug 12, 2020 | A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to re... |
| CVE-2020-8905 | MEDIUM | 6.5 | 0.2% | Aug 12, 2020 | A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should no... |
| CVE-2020-8904 | CRITICAL | 9.6 | 0.2% | Aug 12, 2020 | An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the eca... |
| CVE-2020-12107 | CRITICAL | 9.8 | 2.1% | Aug 12, 2020 | The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full cont... |
| CVE-2020-12106 | CRITICAL | 9.8 | 1.4% | Aug 12, 2020 | The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to severa... |
| CVE-2020-7374 | HIGH | 7.8 | 3.1% | Aug 12, 2020 | Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validat... |
| CVE-2020-17507 | MEDIUM | 5.3 | 3.9% | Aug 12, 2020 | An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmha... |
| CVE-2020-17361 | MEDIUM | 5.5 | 1.2% | Aug 12, 2020 | An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h returns silentl... |
| CVE-2020-17360 | HIGH | 7.8 | 1.2% | Aug 12, 2020 | An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multip... |
| CVE-2020-6653 | LOW | 3.9 | 0.3% | Aug 12, 2020 | Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or re... |
| CVE-2020-5415 | CRITICAL | 10 | 1.2% | Aug 12, 2020 | Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to ide... |
| CVE-2020-2035 | LOW | 3 | 0.8% | Aug 12, 2020 | When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering... |
| CVE-2020-17506 | CRITICAL | 9.8 | 94.0% | Aug 12, 2020 | Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p... |
| CVE-2020-17505 | HIGH | 8.8 | 82.2% | Aug 12, 2020 | Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter i... |
| CVE-2020-15137 | MEDIUM | 5.9 | 0.3% | Aug 12, 2020 | All versions of HoRNDIS are affected by an integer overflow in the RNDIS packet parsing routines. A malicious USB device... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now