2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12627CRITICAL9.8Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.
CVE-2020-12626MEDIUM6.5An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged ou...
CVE-2020-12625MEDIUM6.1An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_...
CVE-2020-12624MEDIUM6.5The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary...
CVE-2020-8157MEDIUM6.8UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unre...
CVE-2020-7645CRITICAL9.8All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in ...
CVE-2020-5727MEDIUM4.6Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated ...
CVE-2020-10683CRITICAL9.8dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE ...
CVE-2020-7351HIGH8.8An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allo...
CVE-2020-12474MEDIUM6.5Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homo...
CVE-2020-12117MEDIUM5.3Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration val...
CVE-2020-11037MEDIUM4.7In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protec...
CVE-2020-11030MEDIUM5.4In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the...
CVE-2020-11029MEDIUM6.1In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited t...
CVE-2020-11028HIGH7.5In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated discl...
CVE-2020-11027HIGH8.1In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user passwo...
CVE-2020-11026MEDIUM5.4In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to sc...
CVE-2020-11016HIGH8.8IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled me...
CVE-2020-9098HIGH7.5Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The softwar...
CVE-2020-6867MEDIUM5.5ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other...
CVE-2020-6866MEDIUM4.9A ZTE product is impacted by a resource management error vulnerability. An attacker could exploit this vulnerability to ...
CVE-2020-6865MEDIUM6.5ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimiz...
CVE-2020-5892MEDIUM6.7In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attack...
CVE-2020-5890MEDIUM5.5On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a Q...
CVE-2020-5888HIGH8.1On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism fo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now