2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12627 | CRITICAL | 9.8 | 1.4% | May 4, 2020 | Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key. |
| CVE-2020-12626 | MEDIUM | 6.5 | 1.8% | May 4, 2020 | An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged ou... |
| CVE-2020-12625 | MEDIUM | 6.1 | 2.8% | May 4, 2020 | An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_... |
| CVE-2020-12624 | MEDIUM | 6.5 | 1.3% | May 3, 2020 | The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary... |
| CVE-2020-8157 | MEDIUM | 6.8 | 0.3% | May 2, 2020 | UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unre... |
| CVE-2020-7645 | CRITICAL | 9.8 | 1.0% | May 2, 2020 | All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in ... |
| CVE-2020-5727 | MEDIUM | 4.6 | 0.4% | May 2, 2020 | Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated ... |
| CVE-2020-10683 | CRITICAL | 9.8 | 7.3% | May 1, 2020 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE ... |
| CVE-2020-7351 | HIGH | 8.8 | 65.2% | May 1, 2020 | An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allo... |
| CVE-2020-12474 | MEDIUM | 6.5 | 2.5% | May 1, 2020 | Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homo... |
| CVE-2020-12117 | MEDIUM | 5.3 | 1.4% | May 1, 2020 | Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration val... |
| CVE-2020-11037 | MEDIUM | 4.7 | 0.3% | Apr 30, 2020 | In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protec... |
| CVE-2020-11030 | MEDIUM | 5.4 | 1.4% | Apr 30, 2020 | In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the... |
| CVE-2020-11029 | MEDIUM | 6.1 | 2.1% | Apr 30, 2020 | In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited t... |
| CVE-2020-11028 | HIGH | 7.5 | 2.3% | Apr 30, 2020 | In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated discl... |
| CVE-2020-11027 | HIGH | 8.1 | 13.6% | Apr 30, 2020 | In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user passwo... |
| CVE-2020-11026 | MEDIUM | 5.4 | 2.1% | Apr 30, 2020 | In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to sc... |
| CVE-2020-11016 | HIGH | 8.8 | 2.3% | Apr 30, 2020 | IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled me... |
| CVE-2020-9098 | HIGH | 7.5 | 0.8% | Apr 30, 2020 | Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The softwar... |
| CVE-2020-6867 | MEDIUM | 5.5 | 0.4% | Apr 30, 2020 | ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other... |
| CVE-2020-6866 | MEDIUM | 4.9 | 0.9% | Apr 30, 2020 | A ZTE product is impacted by a resource management error vulnerability. An attacker could exploit this vulnerability to ... |
| CVE-2020-6865 | MEDIUM | 6.5 | 0.9% | Apr 30, 2020 | ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimiz... |
| CVE-2020-5892 | MEDIUM | 6.7 | 0.3% | Apr 30, 2020 | In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attack... |
| CVE-2020-5890 | MEDIUM | 5.5 | 0.5% | Apr 30, 2020 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a Q... |
| CVE-2020-5888 | HIGH | 8.1 | 0.6% | Apr 30, 2020 | On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism fo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now