2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3126 | LOW | 3.5 | 0.9% | Apr 13, 2020 | vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker... |
| CVE-2020-11734 | MEDIUM | 6.1 | 1.0% | Apr 13, 2020 | cgi-bin/go in CyberSolutions CyberMail 5 or later allows XSS via the ACTION parameter. |
| CVE-2020-8430 | MEDIUM | 6.1 | 0.9% | Apr 13, 2020 | Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive ... |
| CVE-2020-9478 | HIGH | 8.8 | 3.1% | Apr 13, 2020 | An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to ... |
| CVE-2020-11673 | CRITICAL | 9.8 | 3.5% | Apr 13, 2020 | An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipul... |
| CVE-2020-8148 | MEDIUM | 5.3 | 1.0% | Apr 13, 2020 | UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostnam... |
| CVE-2020-1759 | MEDIUM | 6.8 | 1.4% | Apr 13, 2020 | A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vul... |
| CVE-2020-11732 | HIGH | 7.5 | 4.9% | Apr 13, 2020 | The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_ga... |
| CVE-2020-11731 | MEDIUM | 6.1 | 1.2% | Apr 13, 2020 | The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/M... |
| CVE-2020-11725 | HIGH | 7.8 | 0.5% | Apr 12, 2020 | snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later aff... |
| CVE-2020-11724 | HIGH | 7.5 | 2.6% | Apr 12, 2020 | An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demons... |
| CVE-2020-11722 | CRITICAL | 9.8 | 3.9% | Apr 12, 2020 | Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytec... |
| CVE-2020-11721 | MEDIUM | 6.5 | 0.9% | Apr 12, 2020 | load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, wh... |
| CVE-2020-11714 | MEDIUM | 5.4 | 0.7% | Apr 12, 2020 | eten PSG-6528VM 1.1 devices allow XSS via System Contact or System Location. |
| CVE-2020-11713 | HIGH | 7.5 | 2.0% | Apr 12, 2020 | wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks. |
| CVE-2020-11712 | MEDIUM | 6.1 | 1.1% | Apr 12, 2020 | Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field. |
| CVE-2020-11710 | CRITICAL | 9.8 | 33.8% | Apr 12, 2020 | An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces othe... |
| CVE-2020-11709 | HIGH | 7.5 | 1.6% | Apr 12, 2020 | cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, whic... |
| CVE-2020-11708 | CRITICAL | 9.8 | 1.6% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetU... |
| CVE-2020-11707 | HIGH | 8.8 | 1.0% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlin... |
| CVE-2020-11706 | HIGH | 8.8 | 0.5% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such ... |
| CVE-2020-11705 | CRITICAL | 9.8 | 0.9% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to loa... |
| CVE-2020-11704 | MEDIUM | 6.1 | 0.7% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and R... |
| CVE-2020-11703 | HIGH | 7.5 | 0.9% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response... |
| CVE-2020-11702 | MEDIUM | 6.1 | 0.7% | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Re... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now