2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15307 | MEDIUM | 6.1 | 0.7% | Jun 30, 2020 | Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to... |
| CVE-2020-15049 | HIGH | 8.8 | 5.7% | Jun 30, 2020 | An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggli... |
| CVE-2020-14482 | HIGH | 7.8 | 2.6% | Jun 30, 2020 | Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Opening a specially crafted project file may overflow... |
| CVE-2020-15087 | HIGH | 8.8 | 1.1% | Jun 30, 2020 | In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. T... |
| CVE-2020-15085 | MEDIUM | 6.1 | 0.6% | Jun 30, 2020 | In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the ... |
| CVE-2020-13095 | HIGH | 8.8 | 1.9% | Jun 30, 2020 | Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the use... |
| CVE-2020-4044 | HIGH | 7.8 | 2.4% | Jun 30, 2020 | The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious pa... |
| CVE-2020-15084 | CRITICAL | 9.1 | 1.1% | Jun 30, 2020 | In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration i... |
| CVE-2020-9483 | HIGH | 7.5 | 34.6% | Jun 30, 2020 | **Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is ... |
| CVE-2020-14957 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2020-14956 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2020-7816 | HIGH | 7.8 | 1.4% | Jun 30, 2020 | A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticate... |
| CVE-2020-15415 | CRITICAL | 9.8 | 84.6% | Jun 30, 2020 | On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote... |
| CVE-2020-15412 | MEDIUM | 4.3 | 0.7% | Jun 30, 2020 | An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding ... |
| CVE-2020-15411 | CRITICAL | 9.8 | 1.4% | Jun 30, 2020 | An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the atta... |
| CVE-2020-15401 | MEDIUM | 4.4 | 0.4% | Jun 30, 2020 | IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious fl... |
| CVE-2020-15400 | MEDIUM | 4.3 | 0.4% | Jun 30, 2020 | CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS. |
| CVE-2020-15397 | HIGH | 7.8 | 0.5% | Jun 30, 2020 | HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileg... |
| CVE-2020-15396 | HIGH | 7.8 | 0.4% | Jun 30, 2020 | In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. B... |
| CVE-2020-5603 | HIGH | 7.5 | 1.3% | Jun 30, 2020 | Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Conf... |
| CVE-2020-5602 | HIGH | 7.5 | 1.4% | Jun 30, 2020 | Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configura... |
| CVE-2020-5601 | HIGH | 8.8 | 1.6% | Jun 30, 2020 | Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspe... |
| CVE-2020-5588 | MEDIUM | 4.9 | 1.0% | Jun 30, 2020 | Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain uninten... |
| CVE-2020-5587 | MEDIUM | 6.5 | 1.1% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vecto... |
| CVE-2020-5586 | MEDIUM | 4.8 | 0.5% | Jun 30, 2020 | Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now