2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3297 | CRITICAL | 9.8 | 3.0% | Jul 2, 2020 | A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches cou... |
| CVE-2020-5238 | MEDIUM | 6.5 | 1.6% | Jul 1, 2020 | The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs.... |
| CVE-2020-15500 | MEDIUM | 6.1 | 12.2% | Jul 1, 2020 | An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected u... |
| CVE-2020-15490 | CRITICAL | 9.8 | 3.7% | Jul 1, 2020 | An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exi... |
| CVE-2020-15489 | CRITICAL | 9.8 | 3.7% | Jul 1, 2020 | An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulne... |
| CVE-2020-14196 | MEDIUM | 5.3 | 1.7% | Jul 1, 2020 | In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal we... |
| CVE-2020-7688 | HIGH | 7.8 | 0.5% | Jul 1, 2020 | The issue occurs because tagName user input is formatted inside the exec function is executed without any checks. |
| CVE-2020-14057 | CRITICAL | 9.8 | 2.6% | Jul 1, 2020 | Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read... |
| CVE-2020-14056 | CRITICAL | 9.8 | 1.3% | Jul 1, 2020 | Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of th... |
| CVE-2020-14055 | MEDIUM | 6.1 | 0.7% | Jul 1, 2020 | Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insuff... |
| CVE-2020-13619 | CRITICAL | 9.8 | 2.9% | Jul 1, 2020 | php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution. |
| CVE-2020-6089 | HIGH | 7.8 | 2.7% | Jul 1, 2020 | An exploitable code execution vulnerability exists in the ANI file format parser of Leadtools 20. A specially crafted AN... |
| CVE-2020-2500 | MEDIUM | 6.5 | 0.7% | Jul 1, 2020 | This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers... |
| CVE-2020-12498 | HIGH | 7.8 | 2.1% | Jul 1, 2020 | mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds ... |
| CVE-2020-12497 | HIGH | 7.8 | 14.7% | Jul 1, 2020 | PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-bas... |
| CVE-2020-8663 | HIGH | 7.5 | 1.5% | Jul 1, 2020 | Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier may exhaust file descriptors and/or memory when accepting too many conne... |
| CVE-2020-5908 | MEDIUM | 5.5 | 0.3% | Jul 1, 2020 | In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in ... |
| CVE-2020-5907 | HIGH | 7.2 | 1.4% | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorize... |
| CVE-2020-5906 | HIGH | 8.1 | 1.2% | Jul 1, 2020 | In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the acces... |
| CVE-2020-5905 | MEDIUM | 4.3 | 0.7% | Jul 1, 2020 | In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize ... |
| CVE-2020-5904 | HIGH | 8.8 | 0.6% | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSR... |
| CVE-2020-5903 | MEDIUM | 6.1 | 2.2% | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vuln... |
| CVE-2020-5902 | CRITICAL | 9.8 | 100.0% | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic ... |
| CVE-2020-5901 | CRITICAL | 9.6 | 1.5% | Jul 1, 2020 | In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. ... |
| CVE-2020-5899 | HIGH | 7.8 | 0.2% | Jul 1, 2020 | In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the dat... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now