2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13143 | MEDIUM | 6.5 | 5.2% | May 18, 2020 | gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup wit... |
| CVE-2020-8034 | MEDIUM | 6.1 | 1.0% | May 18, 2020 | Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected C... |
| CVE-2020-6093 | MEDIUM | 5.5 | 2.6% | May 18, 2020 | An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A sp... |
| CVE-2020-6092 | HIGH | 7.8 | 42.3% | May 18, 2020 | An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially c... |
| CVE-2020-6074 | HIGH | 8.8 | 40.9% | May 18, 2020 | An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF do... |
| CVE-2020-13136 | HIGH | 7.5 | 1.2% | May 18, 2020 | D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer. |
| CVE-2020-13135 | MEDIUM | 6.5 | 0.8% | May 18, 2020 | D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstra... |
| CVE-2020-11551 | HIGH | 8.8 | 1.7% | May 18, 2020 | An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel... |
| CVE-2020-11550 | MEDIUM | 6.5 | 1.6% | May 18, 2020 | An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel... |
| CVE-2020-11549 | HIGH | 8.8 | 4.1% | May 18, 2020 | An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satel... |
| CVE-2020-8035 | MEDIUM | 6.1 | 0.9% | May 18, 2020 | The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripti... |
| CVE-2020-12801 | MEDIUM | 5.3 | 1.3% | May 18, 2020 | If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffic... |
| CVE-2020-12256 | MEDIUM | 5.4 | 92.8% | May 18, 2020 | rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can ... |
| CVE-2020-12255 | HIGH | 8.8 | 52.6% | May 18, 2020 | rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor... |
| CVE-2020-10967 | MEDIUM | 5.3 | 8.2% | May 18, 2020 | In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail wi... |
| CVE-2020-9524 | MEDIUM | 5.4 | 0.5% | May 18, 2020 | Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions pri... |
| CVE-2020-12258 | CRITICAL | 9.1 | 1.7% | May 18, 2020 | rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application... |
| CVE-2020-12257 | HIGH | 8.8 | 1.4% | May 18, 2020 | rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such... |
| CVE-2020-10958 | MEDIUM | 5.3 | 6.1% | May 18, 2020 | In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-log... |
| CVE-2020-10957 | HIGH | 7.5 | 7.2% | May 18, 2020 | In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dere... |
| CVE-2020-12259 | MEDIUM | 5.4 | 94.8% | May 18, 2020 | rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can... |
| CVE-2020-13129 | HIGH | 7.2 | 1.7% | May 18, 2020 | An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms... |
| CVE-2020-12860 | MEDIUM | 5.3 | 1.0% | May 18, 2020 | COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can h... |
| CVE-2020-12859 | MEDIUM | 5.3 | 0.7% | May 18, 2020 | Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify ... |
| CVE-2020-12858 | HIGH | 7.5 | 1.8% | May 18, 2020 | Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now