2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12063 | MEDIUM | 5.3 | 0.9% | Apr 24, 2020 | A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homog... |
| CVE-2020-12135 | MEDIUM | 5.5 | 1.2% | Apr 24, 2020 | bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular... |
| CVE-2020-12134 | CRITICAL | 9.8 | 1.3% | Apr 24, 2020 | Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log. |
| CVE-2020-12132 | MEDIUM | 6.1 | 0.7% | Apr 24, 2020 | Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request. |
| CVE-2020-12131 | MEDIUM | 6.1 | 0.7% | Apr 24, 2020 | The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo). |
| CVE-2020-12130 | MEDIUM | 6.1 | 0.7% | Apr 24, 2020 | The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function. |
| CVE-2020-12129 | MEDIUM | 6.1 | 0.7% | Apr 24, 2020 | The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function. |
| CVE-2020-12128 | HIGH | 7.5 | 1.6% | Apr 24, 2020 | DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path. |
| CVE-2020-12118 | HIGH | 8.2 | 1.4% | Apr 23, 2020 | The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parame... |
| CVE-2020-11012 | HIGH | 7.5 | 2.1% | Apr 23, 2020 | MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an ... |
| CVE-2020-5867 | HIGH | 8.1 | 0.4% | Apr 23, 2020 | In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check... |
| CVE-2020-8798 | MEDIUM | 5.5 | 0.4% | Apr 23, 2020 | httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the... |
| CVE-2020-5866 | MEDIUM | 5.5 | 0.3% | Apr 23, 2020 | In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to ch... |
| CVE-2020-5865 | MEDIUM | 4.8 | 0.4% | Apr 23, 2020 | In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over une... |
| CVE-2020-5864 | HIGH | 7.4 | 1.0% | Apr 23, 2020 | In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS... |
| CVE-2020-8797 | MEDIUM | 6.7 | 0.9% | Apr 23, 2020 | Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call ... |
| CVE-2020-7132 | MEDIUM | 5.4 | 0.7% | Apr 23, 2020 | A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely... |
| CVE-2020-12113 | MEDIUM | 6.1 | 0.9% | Apr 23, 2020 | BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used. |
| CVE-2020-12112 | HIGH | 7.5 | 5.3% | Apr 23, 2020 | BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion. |
| CVE-2020-12105 | MEDIUM | 5.9 | 1.7% | Apr 23, 2020 | OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers... |
| CVE-2020-7643 | MEDIUM | 5.3 | 1.0% | Apr 23, 2020 | paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function c... |
| CVE-2020-4415 | CRITICAL | 9.8 | 8.1% | Apr 23, 2020 | IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checki... |
| CVE-2020-4353 | MEDIUM | 4.6 | 0.3% | Apr 23, 2020 | IBM MaaS360 6.82 could allow a user with pysical access to the device to crash the application which may enable the user... |
| CVE-2020-4311 | HIGH | 7 | 0.3% | Apr 23, 2020 | IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially... |
| CVE-2020-4202 | HIGH | 8.8 | 1.0% | Apr 23, 2020 | IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the serv... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now