2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6974CRITICAL9.8Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to b...
CVE-2020-11612HIGH7.5The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte st...
CVE-2020-11611MEDIUM6.1An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the ...
CVE-2020-11610HIGH8.8An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js spec...
CVE-2020-9514MEDIUM6.5An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in...
CVE-2020-11609MEDIUM4.3An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06...
CVE-2020-11560HIGH7.8NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
CVE-2020-11516MEDIUM5.4Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minim...
CVE-2020-11515MEDIUM6.1The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that red...
CVE-2020-11514CRITICAL9.8The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPres...
CVE-2020-11512MEDIUM5.4Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subs...
CVE-2020-5302MEDIUM6.5MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access th...
CVE-2020-11561HIGH8.8In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged fun...
CVE-2020-7618MEDIUM5.3sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties ...
CVE-2020-7616MEDIUM5.3express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tri...
CVE-2020-7615HIGH7.8fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep....
CVE-2020-7614CRITICAL9.8npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated t...
CVE-2020-7613HIGH8.1clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_...
CVE-2020-5734HIGH7.5Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by...
CVE-2020-11608MEDIUM4.3An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferenc...
CVE-2020-6171MEDIUM6.1A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote at...
CVE-2020-2176MEDIUM5.4Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from ...
CVE-2020-2175MEDIUM5.4Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI...
CVE-2020-2174MEDIUM6.1Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation out...
CVE-2020-2173MEDIUM5.4Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports ser...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now