2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35230 | MEDIUM | 6.8 | 0.4% | Mar 10, 2021 | Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 d... |
| CVE-2020-35228 | MEDIUM | 4.8 | 0.8% | Mar 10, 2021 | A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 device... |
| CVE-2020-35225 | MEDIUM | 6.8 | 0.6% | Mar 10, 2021 | The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length o... |
| CVE-2020-35224 | MEDIUM | 6.5 | 0.7% | Mar 10, 2021 | A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 device... |
| CVE-2020-5016 | MEDIUM | 6.5 | 2.3% | Mar 10, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys... |
| CVE-2020-4717 | MEDIUM | 5.5 | 0.3% | Mar 10, 2021 | A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permissio... |
| CVE-2020-35752 | MEDIUM | 5.4 | 0.9% | Mar 10, 2021 | Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post tit... |
| CVE-2020-28705 | MEDIUM | 4.3 | 0.6% | Mar 10, 2021 | FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /page... |
| CVE-2020-23721 | MEDIUM | 5.4 | 0.6% | Mar 10, 2021 | An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages... |
| CVE-2020-13959 | MEDIUM | 6.1 | 6.4% | Mar 10, 2021 | The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered... |
| CVE-2020-35522 | MEDIUM | 5.5 | 1.6% | Mar 9, 2021 | In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting ... |
| CVE-2020-35521 | MEDIUM | 5.5 | 1.2% | Mar 9, 2021 | A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort,... |
| CVE-2020-28150 | MEDIUM | 6.1 | 0.9% | Mar 9, 2021 | I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an exter... |
| CVE-2020-8357 | MEDIUM | 5.5 | 0.2% | Mar 9, 2021 | A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow conf... |
| CVE-2020-8356 | MEDIUM | 4.9 | 0.5% | Mar 9, 2021 | An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, fo... |
| CVE-2020-35451 | MEDIUM | 4.7 | 0.4% | Mar 9, 2021 | There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to ... |
| CVE-2020-27838 | MEDIUM | 6.5 | 17.9% | Mar 8, 2021 | A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information a... |
| CVE-2020-27576 | MEDIUM | 5.4 | 0.6% | Mar 8, 2021 | Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web ap... |
| CVE-2020-5014 | MEDIUM | 6.7 | 0.9% | Mar 8, 2021 | IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary cod... |
| CVE-2020-4903 | MEDIUM | 6.5 | 0.7% | Mar 8, 2021 | IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate ... |
| CVE-2020-29029 | MEDIUM | 6.1 | 0.8% | Mar 5, 2021 | Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker... |
| CVE-2020-29028 | MEDIUM | 6.1 | 0.7% | Mar 5, 2021 | Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javasc... |
| CVE-2020-35594 | MEDIUM | 6.1 | 1.0% | Mar 5, 2021 | Zoho ManageEngine ADManager Plus before 7066 allows XSS. |
| CVE-2020-25639 | MEDIUM | 4.4 | 0.4% | Mar 4, 2021 | A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.... |
| CVE-2020-4975 | MEDIUM | 5.4 | 0.5% | Mar 4, 2021 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now