2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13912 | HIGH | 7.3 | 1.1% | Jun 7, 2020 | SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, b... |
| CVE-2020-13910 | CRITICAL | 9.1 | 1.2% | Jun 7, 2020 | Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an in... |
| CVE-2020-13909 | CRITICAL | 9.8 | 1.5% | Jun 7, 2020 | The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x ser... |
| CVE-2020-13904 | MEDIUM | 5.5 | 1.3% | Jun 7, 2020 | FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavf... |
| CVE-2020-13902 | HIGH | 7.1 | 1.0% | Jun 7, 2020 | ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c duri... |
| CVE-2020-13897 | MEDIUM | 6.1 | 0.6% | Jun 7, 2020 | HESK before 3.1.10 allows reflected XSS. |
| CVE-2020-13895 | HIGH | 8.8 | 0.7% | Jun 7, 2020 | Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA sign... |
| CVE-2020-13894 | HIGH | 7.5 | 1.1% | Jun 7, 2020 | handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the sa... |
| CVE-2020-13890 | MEDIUM | 5.4 | 0.5% | Jun 6, 2020 | The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard. |
| CVE-2020-13889 | MEDIUM | 5.4 | 0.9% | Jun 6, 2020 | showAlert() in the administration panel in Bludit 3.12.0 allows XSS. |
| CVE-2020-13883 | MEDIUM | 6.7 | 0.8% | Jun 6, 2020 | In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Manage... |
| CVE-2020-13881 | HIGH | 7.5 | 1.7% | Jun 6, 2020 | In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel ... |
| CVE-2020-13871 | HIGH | 7.5 | 4.4% | Jun 6, 2020 | SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions i... |
| CVE-2020-13865 | MEDIUM | 5.4 | 0.8% | Jun 5, 2020 | The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author... |
| CVE-2020-13864 | MEDIUM | 5.4 | 0.8% | Jun 5, 2020 | The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can... |
| CVE-2020-11696 | MEDIUM | 6.1 | 0.7% | Jun 5, 2020 | In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (com... |
| CVE-2020-13646 | HIGH | 7.8 | 0.4% | Jun 5, 2020 | In Cheetah free WiFi 5.1, the driver file (liebaonat.sys) allows local users to cause a denial of service (BSOD) or poss... |
| CVE-2020-11697 | MEDIUM | 6.1 | 0.7% | Jun 5, 2020 | In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (commu... |
| CVE-2020-13870 | MEDIUM | 5.4 | 0.5% | Jun 5, 2020 | An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name. |
| CVE-2020-13869 | MEDIUM | 5.4 | 0.5% | Jun 5, 2020 | An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name. |
| CVE-2020-13868 | MEDIUM | 6.5 | 0.4% | Jun 5, 2020 | An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. |
| CVE-2020-5591 | HIGH | 7.5 | 1.6% | Jun 5, 2020 | XACK DNS 1.11.0 to 1.11.4, 1.10.0 to 1.10.8, 1.8.0 to 1.8.23, 1.7.0 to 1.7.18, and versions before 1.7.0 allow remote at... |
| CVE-2020-13867 | MEDIUM | 5.5 | 0.3% | Jun 5, 2020 | Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup fil... |
| CVE-2020-10071 | CRITICAL | 9.8 | 3.4% | Jun 5, 2020 | The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer o... |
| CVE-2020-10070 | CRITICAL | 9.8 | 2.9% | Jun 5, 2020 | In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execu... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now