2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6974 | CRITICAL | 9.8 | 1.9% | Apr 7, 2020 | Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to b... |
| CVE-2020-11612 | HIGH | 7.5 | 9.4% | Apr 7, 2020 | The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte st... |
| CVE-2020-11611 | MEDIUM | 6.1 | 0.9% | Apr 7, 2020 | An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the ... |
| CVE-2020-11610 | HIGH | 8.8 | 1.4% | Apr 7, 2020 | An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js spec... |
| CVE-2020-9514 | MEDIUM | 6.5 | 1.0% | Apr 7, 2020 | An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in... |
| CVE-2020-11609 | MEDIUM | 4.3 | 0.6% | Apr 7, 2020 | An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06... |
| CVE-2020-11560 | HIGH | 7.8 | 1.0% | Apr 7, 2020 | NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. |
| CVE-2020-11516 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minim... |
| CVE-2020-11515 | MEDIUM | 6.1 | 2.1% | Apr 7, 2020 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that red... |
| CVE-2020-11514 | CRITICAL | 9.8 | 9.1% | Apr 7, 2020 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPres... |
| CVE-2020-11512 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subs... |
| CVE-2020-5302 | MEDIUM | 6.5 | 0.9% | Apr 7, 2020 | MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access th... |
| CVE-2020-11561 | HIGH | 8.8 | 2.2% | Apr 7, 2020 | In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged fun... |
| CVE-2020-7618 | MEDIUM | 5.3 | 1.1% | Apr 7, 2020 | sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties ... |
| CVE-2020-7616 | MEDIUM | 5.3 | 1.2% | Apr 7, 2020 | express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tri... |
| CVE-2020-7615 | HIGH | 7.8 | 1.1% | Apr 7, 2020 | fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.... |
| CVE-2020-7614 | CRITICAL | 9.8 | 3.5% | Apr 7, 2020 | npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated t... |
| CVE-2020-7613 | HIGH | 8.1 | 2.1% | Apr 7, 2020 | clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_... |
| CVE-2020-5734 | HIGH | 7.5 | 25.1% | Apr 7, 2020 | Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by... |
| CVE-2020-11608 | MEDIUM | 4.3 | 0.5% | Apr 7, 2020 | An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferenc... |
| CVE-2020-6171 | MEDIUM | 6.1 | 4.8% | Apr 7, 2020 | A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote at... |
| CVE-2020-2176 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from ... |
| CVE-2020-2175 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI... |
| CVE-2020-2174 | MEDIUM | 6.1 | 0.8% | Apr 7, 2020 | Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation out... |
| CVE-2020-2173 | MEDIUM | 5.4 | 0.7% | Apr 7, 2020 | Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports ser... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now