2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35542 | MEDIUM | 5.4 | 0.5% | Apr 27, 2021 | Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be... |
| CVE-2020-4562 | MEDIUM | 5.3 | 1.3% | Apr 26, 2021 | IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window commun... |
| CVE-2020-7036 | MEDIUM | 6.5 | 1.0% | Apr 23, 2021 | An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain rea... |
| CVE-2020-7035 | MEDIUM | 6.5 | 1.1% | Apr 23, 2021 | An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could a... |
| CVE-2020-17542 | MEDIUM | 5.4 | 0.8% | Apr 23, 2021 | Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious p... |
| CVE-2020-36319 | MEDIUM | 6.5 | 1.0% | Apr 23, 2021 | Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 thr... |
| CVE-2020-27737 | MEDIUM | 6.5 | 3.6% | Apr 22, 2021 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether... |
| CVE-2020-27736 | MEDIUM | 6.5 | 3.6% | Apr 22, 2021 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether... |
| CVE-2020-25243 | MEDIUM | 5.1 | 0.3% | Apr 22, 2021 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be trigg... |
| CVE-2020-36324 | MEDIUM | 6.1 | 0.6% | Apr 21, 2021 | Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the ... |
| CVE-2020-23932 | MEDIUM | 5.5 | 0.8% | Apr 21, 2021 | An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in... |
| CVE-2020-23930 | MEDIUM | 5.5 | 0.7% | Apr 21, 2021 | An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header... |
| CVE-2020-23915 | MEDIUM | 5.5 | 0.9% | Apr 21, 2021 | An issue was discovered in cpp-peglib through v0.1.12. peg::resolve_escape_sequence() in peglib.h has a heap-based buffe... |
| CVE-2020-23914 | MEDIUM | 5.5 | 0.9% | Apr 21, 2021 | An issue was discovered in cpp-peglib through v0.1.12. A NULL pointer dereference exists in the peg::AstOptimizer::optim... |
| CVE-2020-23912 | MEDIUM | 5.5 | 0.7% | Apr 21, 2021 | An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::Ge... |
| CVE-2020-25864 | MEDIUM | 6.1 | 6.1% | Apr 20, 2021 | HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scriptin... |
| CVE-2020-14105 | MEDIUM | 5.5 | 0.3% | Apr 20, 2021 | The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15. |
| CVE-2020-28141 | MEDIUM | 5.4 | 0.6% | Apr 19, 2021 | The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated us... |
| CVE-2020-9681 | MEDIUM | 6.5 | 0.7% | Apr 16, 2021 | Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut... |
| CVE-2020-9667 | MEDIUM | 6.5 | 0.5% | Apr 16, 2021 | Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut... |
| CVE-2020-28898 | MEDIUM | 5.3 | 1.3% | Apr 15, 2021 | In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a ... |
| CVE-2020-7308 | MEDIUM | 6.5 | 0.5% | Apr 15, 2021 | Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Febru... |
| CVE-2020-7270 | MEDIUM | 4.3 | 0.8% | Apr 15, 2021 | Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re... |
| CVE-2020-7269 | MEDIUM | 4.3 | 0.7% | Apr 15, 2021 | Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re... |
| CVE-2020-36288 | MEDIUM | 6.1 | 1.5% | Apr 15, 2021 | The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before ver... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now