2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26158 | CRITICAL | 9.6 | 1.9% | Sep 30, 2020 | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This ... |
| CVE-2020-26157 | CRITICAL | 9.6 | 1.9% | Sep 30, 2020 | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code ... |
| CVE-2020-26154 | CRITICAL | 9.8 | 3.6% | Sep 30, 2020 | url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC fil... |
| CVE-2020-26042 | CRITICAL | 9.8 | 1.2% | Sep 30, 2020 | An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php |
| CVE-2020-26041 | CRITICAL | 9.8 | 2.8% | Sep 30, 2020 | An issue was discovered in Hoosk CmS v1.8.0. There is an Remote Code Execution vulnerability in install/index.php |
| CVE-2020-25763 | CRITICAL | 9.8 | 5.0% | Sep 30, 2020 | Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers ... |
| CVE-2020-25762 | CRITICAL | 9.1 | 11.3% | Sep 30, 2020 | An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v... |
| CVE-2020-21526 | CRITICAL | 9.8 | 1.9% | Sep 30, 2020 | An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory tr... |
| CVE-2020-21524 | CRITICAL | 9.1 | 1.5% | Sep 30, 2020 | There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the backgrou... |
| CVE-2020-21523 | CRITICAL | 9.8 | 2.6% | Sep 30, 2020 | A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl fi... |
| CVE-2020-21522 | CRITICAL | 9.8 | 1.5% | Sep 30, 2020 | An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can ove... |
| CVE-2020-20800 | CRITICAL | 9.8 | 1.5% | Sep 30, 2020 | An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndat... |
| CVE-2020-19672 | CRITICAL | 9.8 | 1.3% | Sep 30, 2020 | Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface... |
| CVE-2020-15487 | CRITICAL | 9.8 | 3.7% | Sep 30, 2020 | Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protec... |
| CVE-2020-12506 | CRITICAL | 9.1 | 1.5% | Sep 30, 2020 | Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the se... |
| CVE-2020-15208 | CRITICAL | 9.8 | 0.9% | Sep 25, 2020 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of ... |
| CVE-2020-15207 | CRITICAL | 9 | 1.2% | Sep 25, 2020 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative value... |
| CVE-2020-15205 | CRITICAL | 9.8 | 1.0% | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGr... |
| CVE-2020-15202 | CRITICAL | 9 | 1.2% | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argu... |
| CVE-2020-15196 | CRITICAL | 9.9 | 0.9% | Sep 25, 2020 | In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate ... |
| CVE-2020-25147 | CRITICAL | 9.8 | 1.4% | Sep 25, 2020 | An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection ... |
| CVE-2020-25132 | CRITICAL | 9.8 | 1.6% | Sep 25, 2020 | An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection ... |
| CVE-2020-15374 | CRITICAL | 9.8 | 1.2% | Sep 25, 2020 | Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c is vulnerable to multiple instan... |
| CVE-2020-15373 | CRITICAL | 9.8 | 2.4% | Sep 25, 2020 | Multiple buffer overflow vulnerabilities in REST API in Brocade Fabric OS versions v8.2.1 through v8.2.1d, and 8.2.2 ver... |
| CVE-2020-15371 | CRITICAL | 9.8 | 1.3% | Sep 25, 2020 | Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code inject... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now