2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10916 | HIGH | 8 | 1.1% | May 7, 2020 | This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA85... |
| CVE-2020-9475 | HIGH | 7 | 0.3% | May 7, 2020 | The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows local privilege escalation via a race condition in log... |
| CVE-2020-9474 | HIGH | 8.8 | 1.9% | May 7, 2020 | The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows remote code execution via the backup functionality in ... |
| CVE-2020-11056 | MEDIUM | 6.3 | 1.0% | May 7, 2020 | In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields... |
| CVE-2020-11055 | MEDIUM | 5.4 | 0.8% | May 7, 2020 | In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A ... |
| CVE-2020-11054 | LOW | 3.5 | 1.3% | May 7, 2020 | In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificat... |
| CVE-2020-11053 | MEDIUM | 6.1 | 0.8% | May 7, 2020 | In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the prox... |
| CVE-2020-11052 | CRITICAL | 9.8 | 1.6% | May 7, 2020 | In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute... |
| CVE-2020-11050 | HIGH | 8.1 | 0.8% | May 7, 2020 | In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where W... |
| CVE-2020-10795 | HIGH | 7.2 | 3.8% | May 7, 2020 | Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web... |
| CVE-2020-10794 | CRITICAL | 9.8 | 1.4% | May 7, 2020 | Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the appl... |
| CVE-2020-10176 | CRITICAL | 9.8 | 2.3% | May 7, 2020 | ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands. |
| CVE-2020-4430 | MEDIUM | 4.3 | 68.5% | May 7, 2020 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories... |
| CVE-2020-4429 | CRITICAL | 9.8 | 71.4% | May 7, 2020 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ... |
| CVE-2020-4428 | CRITICAL | 9.1 | 61.7% | May 7, 2020 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary co... |
| CVE-2020-4427 | CRITICAL | 9.8 | 70.0% | May 7, 2020 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest... |
| CVE-2020-12708 | MEDIUM | 6.1 | 0.9% | May 7, 2020 | Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web scrip... |
| CVE-2020-12707 | MEDIUM | 6.1 | 1.2% | May 7, 2020 | An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only secur... |
| CVE-2020-12706 | MEDIUM | 5.4 | 2.9% | May 7, 2020 | Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web scrip... |
| CVE-2020-12705 | MEDIUM | 6.1 | 0.6% | May 7, 2020 | Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0. |
| CVE-2020-12704 | MEDIUM | 6.1 | 1.2% | May 7, 2020 | UliCMS before 2020.2 has PageController stored XSS. |
| CVE-2020-12703 | MEDIUM | 6.1 | 0.6% | May 7, 2020 | UliCMS before 2020.2 has XSS during PackageController uninstall. |
| CVE-2020-12116 | HIGH | 7.5 | 97.4% | May 7, 2020 | Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attack... |
| CVE-2020-11049 | LOW | 2.2 | 1.5% | May 7, 2020 | In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the prot... |
| CVE-2020-11048 | LOW | 2.2 | 1.8% | May 7, 2020 | In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extrac... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now