2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-19642 | MEDIUM | 6.2 | 0.4% | Mar 30, 2021 | An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitra... |
| CVE-2020-7464 | MEDIUM | 5.3 | 0.7% | Mar 26, 2021 | In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and ... |
| CVE-2020-7463 | MEDIUM | 5.5 | 0.4% | Mar 26, 2021 | In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 1... |
| CVE-2020-7462 | MEDIUM | 5.5 | 0.2% | Mar 26, 2021 | In 11.4-PRERELEASE before r360733 and 11.3-RELEASE before p13, improper mbuf handling in the kernel causes a use-after-f... |
| CVE-2020-25580 | MEDIUM | 5.3 | 0.7% | Mar 26, 2021 | In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a r... |
| CVE-2020-25579 | MEDIUM | 5.3 | 1.1% | Mar 26, 2021 | In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 1... |
| CVE-2020-25578 | MEDIUM | 5.3 | 2.3% | Mar 26, 2021 | In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 1... |
| CVE-2020-35518 | MEDIUM | 5.3 | 1.5% | Mar 26, 2021 | When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or n... |
| CVE-2020-35508 | MEDIUM | 4.5 | 0.2% | Mar 26, 2021 | A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/... |
| CVE-2020-27829 | MEDIUM | 5.5 | 1.2% | Mar 26, 2021 | A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.... |
| CVE-2020-35856 | MEDIUM | 4.8 | 0.7% | Mar 26, 2021 | SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page. |
| CVE-2020-19626 | MEDIUM | 5.4 | 0.8% | Mar 26, 2021 | Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or H... |
| CVE-2020-25840 | MEDIUM | 6.1 | 0.6% | Mar 26, 2021 | Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The ... |
| CVE-2020-23517 | MEDIUM | 6.1 | 7.1% | Mar 26, 2021 | Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers... |
| CVE-2020-15809 | MEDIUM | 6.5 | 0.9% | Mar 24, 2021 | spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversa... |
| CVE-2020-12483 | MEDIUM | 6.1 | 0.7% | Mar 23, 2021 | The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps... |
| CVE-2020-9212 | MEDIUM | 6.5 | 0.6% | Mar 22, 2021 | There is a vulnerability in some version of USG9500 that the device improperly handles the information when a user logs ... |
| CVE-2020-9206 | MEDIUM | 6.7 | 0.2% | Mar 22, 2021 | The eUDC660 product has a resource management vulnerability. An attacker with high privilege needs to perform specific o... |
| CVE-2020-4882 | MEDIUM | 6.1 | 0.7% | Mar 22, 2021 | IBM Planning Analytics 2.0 could be vulnerable to a Server-Side Request Forgery (SSRF) attack by constucting URLs from u... |
| CVE-2020-27171 | MEDIUM | 6 | 0.6% | Mar 20, 2021 | An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resulta... |
| CVE-2020-27170 | MEDIUM | 4.7 | 0.6% | Mar 20, 2021 | An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds spec... |
| CVE-2020-4635 | MEDIUM | 5.3 | 0.9% | Mar 19, 2021 | IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames. |
| CVE-2020-6578 | MEDIUM | 6.1 | 0.8% | Mar 19, 2021 | Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_... |
| CVE-2020-36144 | MEDIUM | 5.3 | 0.9% | Mar 18, 2021 | Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escapi... |
| CVE-2020-17457 | MEDIUM | 5.4 | 0.5% | Mar 17, 2021 | Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FI... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now