2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5612 | MEDIUM | 6.1 | 1.1% | Jul 29, 2020 | Cross-site scripting vulnerability in KonaWiki 2.2.0 and earlier allows remote attackers to execute an arbitrary script ... |
| CVE-2020-6098 | HIGH | 7.5 | 1.8% | Jul 28, 2020 | An exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A special... |
| CVE-2020-13997 | HIGH | 7.5 | 1.5% | Jul 28, 2020 | In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and v... |
| CVE-2020-13971 | MEDIUM | 5.4 | 0.6% | Jul 28, 2020 | In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG image... |
| CVE-2020-13970 | HIGH | 8.8 | 1.3% | Jul 28, 2020 | Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature.... |
| CVE-2020-11476 | HIGH | 7.2 | 2.9% | Jul 28, 2020 | Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file. |
| CVE-2020-11474 | HIGH | 7.8 | 0.5% | Jul 28, 2020 | NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant. |
| CVE-2020-10985 | MEDIUM | 4.8 | 0.6% | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php. |
| CVE-2020-10984 | HIGH | 8.8 | 0.7% | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows admin/admin.php CSRF. |
| CVE-2020-10983 | MEDIUM | 4.9 | 1.4% | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php. |
| CVE-2020-10982 | MEDIUM | 4.9 | 1.4% | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php. |
| CVE-2020-16094 | HIGH | 7.5 | 1.8% | Jul 28, 2020 | In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because ... |
| CVE-2020-5377 | CRITICAL | 9.1 | 48.3% | Jul 28, 2020 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. ... |
| CVE-2020-15899 | HIGH | 7.5 | 0.8% | Jul 28, 2020 | Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble. |
| CVE-2020-15419 | HIGH | 7.5 | 63.8% | Jul 28, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0... |
| CVE-2020-15418 | HIGH | 7.5 | 9.4% | Jul 28, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0... |
| CVE-2020-15417 | MEDIUM | 6.3 | 1.3% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
| CVE-2020-15416 | HIGH | 8.8 | 6.4% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700... |
| CVE-2020-10930 | MEDIUM | 6.5 | 0.9% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG... |
| CVE-2020-10929 | HIGH | 8.8 | 1.9% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
| CVE-2020-10928 | HIGH | 8.4 | 0.6% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
| CVE-2020-10927 | HIGH | 8.8 | 0.9% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
| CVE-2020-10926 | HIGH | 8.8 | 1.2% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
| CVE-2020-10925 | HIGH | 8.8 | 1.4% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i... |
| CVE-2020-10924 | HIGH | 8.8 | 87.3% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now