2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13432 | HIGH | 7.5 | 32.8% | Jun 8, 2020 | rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to ... |
| CVE-2020-10754 | MEDIUM | 4.3 | 1.0% | Jun 8, 2020 | It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-p... |
| CVE-2020-8954 | MEDIUM | 5.4 | 0.8% | Jun 8, 2020 | OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manip... |
| CVE-2020-5304 | HIGH | 7.5 | 1.0% | Jun 8, 2020 | The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a... |
| CVE-2020-13696 | MEDIUM | 4.4 | 0.4% | Jun 8, 2020 | An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient... |
| CVE-2020-13625 | HIGH | 7.5 | 3.8% | Jun 8, 2020 | PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote charac... |
| CVE-2020-12800 | CRITICAL | 9.8 | 78.8% | Jun 8, 2020 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa... |
| CVE-2020-12695 | HIGH | 7.5 | 15.2% | Jun 8, 2020 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription r... |
| CVE-2020-12049 | MEDIUM | 5.5 | 0.6% | Jun 8, 2020 | An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file d... |
| CVE-2020-9042 | HIGH | 8.8 | 0.6% | Jun 8, 2020 | In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has us... |
| CVE-2020-9041 | HIGH | 7.5 | 1.3% | Jun 8, 2020 | In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text ... |
| CVE-2020-9040 | HIGH | 7.5 | 0.7% | Jun 8, 2020 | Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intende... |
| CVE-2020-1775 | MEDIUM | 4.3 | 0.8% | Jun 8, 2020 | BCC recipients in mails sent from OTRS are visible in article detail on external interface. This issue affects OTRS: 8.0... |
| CVE-2020-13866 | HIGH | 7.8 | 1.1% | Jun 8, 2020 | WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges... |
| CVE-2020-12803 | MEDIUM | 6.5 | 1.7% | Jun 8, 2020 | ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be subm... |
| CVE-2020-12802 | MEDIUM | 5.3 | 1.9% | Jun 8, 2020 | LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote ... |
| CVE-2020-9099 | CRITICAL | 9.8 | 0.9% | Jun 8, 2020 | Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6... |
| CVE-2020-8180 | CRITICAL | 9.9 | 1.7% | Jun 8, 2020 | A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk co... |
| CVE-2020-8172 | HIGH | 7.4 | 6.1% | Jun 8, 2020 | TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. |
| CVE-2020-7676 | MEDIUM | 5.4 | 2.1% | Jun 8, 2020 | angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code in... |
| CVE-2020-6110 | HIGH | 8.8 | 4.3% | Jun 8, 2020 | An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages incl... |
| CVE-2020-6109 | CRITICAL | 9.8 | 4.9% | Jun 8, 2020 | An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including anima... |
| CVE-2020-4529 | HIGH | 7.4 | 0.8% | Jun 8, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authe... |
| CVE-2020-12773 | HIGH | 8.8 | 1.2% | Jun 8, 2020 | A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows at... |
| CVE-2020-13912 | HIGH | 7.3 | 1.1% | Jun 7, 2020 | SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, b... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now