2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5585 | MEDIUM | 4.8 | 0.5% | Jun 30, 2020 | Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to inject a... |
| CVE-2020-5584 | HIGH | 7.5 | 1.3% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allow remote attackers to obtain unintended information via unspecified vectors. |
| CVE-2020-5583 | MEDIUM | 6.5 | 1.0% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to obtain unauthorized M... |
| CVE-2020-5582 | MEDIUM | 4.3 | 0.8% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for th... |
| CVE-2020-5581 | MEDIUM | 6.5 | 1.8% | Jun 30, 2020 | Path traversal vulnerability in Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to obtain unintended ... |
| CVE-2020-5580 | HIGH | 8.1 | 1.1% | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to view and/or alter Sin... |
| CVE-2020-15395 | HIGH | 7.8 | 1.1% | Jun 30, 2020 | In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multi... |
| CVE-2020-15393 | MEDIUM | 5.5 | 0.4% | Jun 29, 2020 | In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebe... |
| CVE-2020-15389 | MEDIUM | 6.5 | 2.6% | Jun 29, 2020 | jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and... |
| CVE-2020-15368 | MEDIUM | 5.5 | 1.3% | Jun 29, 2020 | AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering ... |
| CVE-2020-4067 | HIGH | 7.5 | 1.8% | Jun 29, 2020 | In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There... |
| CVE-2020-4037 | MEDIUM | 5.4 | 0.9% | Jun 29, 2020 | In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to se... |
| CVE-2020-15069 | CRITICAL | 9.8 | 10.7% | Jun 29, 2020 | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks f... |
| CVE-2020-15043 | MEDIUM | 6.5 | 0.4% | Jun 29, 2020 | iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the... |
| CVE-2020-14145 | MEDIUM | 5.9 | 2.1% | Jun 29, 2020 | The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm... |
| CVE-2020-14002 | MEDIUM | 5.9 | 3.1% | Jun 29, 2020 | PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This ... |
| CVE-2020-13896 | MEDIUM | 5.3 | 14.8% | Jun 29, 2020 | The web interface of Maipu MP1800X-50 7.5.3.14(R) devices allows remote attackers to obtain sensitive information via th... |
| CVE-2020-13657 | MEDIUM | 5.5 | 0.4% | Jun 29, 2020 | An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to imprope... |
| CVE-2020-15362 | CRITICAL | 9.8 | 2.5% | Jun 29, 2020 | wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite th... |
| CVE-2020-15356 | — | — | — | Jun 29, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-15355 | — | — | — | Jun 29, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-15354 | — | — | — | Jun 29, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-14414 | HIGH | 8.8 | 3.7% | Jun 29, 2020 | NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST reque... |
| CVE-2020-14413 | MEDIUM | 6.1 | 3.4% | Jun 29, 2020 | NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function at... |
| CVE-2020-14412 | HIGH | 8.8 | 3.7% | Jun 29, 2020 | NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacters from a ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now