2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-3126LOW3.5vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker...
CVE-2020-11734MEDIUM6.1cgi-bin/go in CyberSolutions CyberMail 5 or later allows XSS via the ACTION parameter.
CVE-2020-8430MEDIUM6.1Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive ...
CVE-2020-9478HIGH8.8An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to ...
CVE-2020-11673CRITICAL9.8An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipul...
CVE-2020-8148MEDIUM5.3UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostnam...
CVE-2020-1759MEDIUM6.8A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vul...
CVE-2020-11732HIGH7.5The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_ga...
CVE-2020-11731MEDIUM6.1The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/M...
CVE-2020-11725HIGH7.8snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later aff...
CVE-2020-11724HIGH7.5An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demons...
CVE-2020-11722CRITICAL9.8Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytec...
CVE-2020-11721MEDIUM6.5load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, wh...
CVE-2020-11714MEDIUM5.4eten PSG-6528VM 1.1 devices allow XSS via System Contact or System Location.
CVE-2020-11713HIGH7.5wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks.
CVE-2020-11712MEDIUM6.1Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field.
CVE-2020-11710CRITICAL9.8An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces othe...
CVE-2020-11709HIGH7.5cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, whic...
CVE-2020-11708CRITICAL9.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetU...
CVE-2020-11707HIGH8.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlin...
CVE-2020-11706HIGH8.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such ...
CVE-2020-11705CRITICAL9.8An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to loa...
CVE-2020-11704MEDIUM6.1An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and R...
CVE-2020-11703HIGH7.5An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response...
CVE-2020-11702MEDIUM6.1An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Re...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now