2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15046HIGH8.8The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to...
CVE-2020-15005LOW3.1In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching se...
CVE-2020-15041MEDIUM4.8PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.
CVE-2020-5962HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component, in whic...
CVE-2020-15038MEDIUM5.4The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
CVE-2020-13247HIGH7.3BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled duri...
CVE-2020-15026MEDIUM4.9Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file do...
CVE-2020-15025MEDIUM4.9ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory ...
CVE-2020-13248MEDIUM5.4BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON ...
CVE-2020-3962HIGH8.2VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), ...
CVE-2020-14473CRITICAL9.8Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.
CVE-2020-14472CRITICAL9.8On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities...
CVE-2020-11961HIGH7.5Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get...
CVE-2020-11960CRITICAL9.8Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let...
CVE-2020-11959HIGH7.5An unsafe configuration of nginx lead to information leak in Xiaomi router R3600 ROM before 1.0.50.
CVE-2020-10561CRITICAL9.8An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web...
CVE-2020-9494HIGH7.5Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADE...
CVE-2020-6870HIGH8The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit t...
CVE-2020-3969HIGH7.8VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), ...
CVE-2020-14095CRITICAL9.8In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web in...
CVE-2020-14094CRITICAL9.8In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting ...
CVE-2020-15015MEDIUM6.1The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document.
CVE-2020-14018MEDIUM6.1An issue was discovered in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to v...
CVE-2020-14017HIGH7.5An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are ...
CVE-2020-14016MEDIUM5.3An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now