2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7947CRITICAL9.8An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain...
CVE-2020-6753MEDIUM6.1The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-202...
CVE-2020-5392MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings...
CVE-2020-5391HIGH8.8Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain fi...
CVE-2020-5548HIGH7.5Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01....
CVE-2020-7263MEDIUM6.7Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current vers...
CVE-2020-7066MEDIUM4.3In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-suppli...
CVE-2020-7065HIGH8.8In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, c...
CVE-2020-7064MEDIUM5.4In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data...
CVE-2020-11445MEDIUM5.3TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive informatio...
CVE-2020-5344CRITICAL9.8Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer ove...
CVE-2020-10696HIGH8.8A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into ...
CVE-2020-7009HIGH8.8Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker...
CVE-2020-5292HIGH8.8Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/att...
CVE-2020-5291HIGH7.8Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespace...
CVE-2020-1712HIGH7.8A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are ...
CVE-2020-11441MEDIUM6.1phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF s...
CVE-2020-6008CRITICAL9.8LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution
CVE-2020-4242HIGH8.8IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to ex...
CVE-2020-4241HIGH8.8IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to ex...
CVE-2020-4240MEDIUM6.5IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An ...
CVE-2020-4239MEDIUM5.3IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a ...
CVE-2020-4238HIGH8.8IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an atta...
CVE-2020-4237HIGH8.8IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an atta...
CVE-2020-4236MEDIUM6.5IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now