2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1773 | HIGH | 8.1 | 1.5% | Mar 27, 2020 | An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or b... |
| CVE-2020-1772 | HIGH | 7.5 | 1.6% | Mar 27, 2020 | It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid... |
| CVE-2020-1771 | MEDIUM | 5.4 | 0.8% | Mar 27, 2020 | Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When age... |
| CVE-2020-1770 | MEDIUM | 4.3 | 1.3% | Mar 27, 2020 | Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue af... |
| CVE-2020-1769 | MEDIUM | 4.3 | 1.3% | Mar 27, 2020 | In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be co... |
| CVE-2020-10510 | MEDIUM | 6.5 | 1.1% | Mar 27, 2020 | Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. Afte... |
| CVE-2020-10509 | MEDIUM | 6.1 | 0.8% | Mar 27, 2020 | Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), a... |
| CVE-2020-10508 | HIGH | 7.5 | 1.5% | Mar 27, 2020 | Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a spe... |
| CVE-2020-3936 | CRITICAL | 9.8 | 1.2% | Mar 27, 2020 | UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, ... |
| CVE-2020-3921 | HIGH | 7.5 | 0.7% | Mar 27, 2020 | UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts informa... |
| CVE-2020-3920 | HIGH | 8.1 | 0.8% | Mar 27, 2020 | UltraLog Express device management interface does not properly perform access authentication in some specific pages/func... |
| CVE-2020-10993 | CRITICAL | 9.1 | 1.3% | Mar 27, 2020 | Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java. |
| CVE-2020-10992 | CRITICAL | 9.8 | 1.3% | Mar 27, 2020 | Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. |
| CVE-2020-10991 | CRITICAL | 9.8 | 1.3% | Mar 27, 2020 | Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java |
| CVE-2020-10990 | CRITICAL | 9.8 | 1.2% | Mar 27, 2020 | An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.j... |
| CVE-2020-9468 | MEDIUM | 4.3 | 0.6% | Mar 26, 2020 | The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do n... |
| CVE-2020-9467 | MEDIUM | 5.4 | 23.8% | Mar 26, 2020 | Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. |
| CVE-2020-10828 | CRITICAL | 9.8 | 20.9% | Mar 26, 2020 | A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote ... |
| CVE-2020-10827 | CRITICAL | 9.8 | 20.9% | Mar 26, 2020 | A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote ... |
| CVE-2020-10826 | CRITICAL | 9.8 | 39.4% | Mar 26, 2020 | /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to ach... |
| CVE-2020-10825 | CRITICAL | 9.8 | 4.0% | Mar 26, 2020 | A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigo... |
| CVE-2020-10824 | CRITICAL | 9.8 | 4.0% | Mar 26, 2020 | A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vig... |
| CVE-2020-10823 | CRITICAL | 9.8 | 4.3% | Mar 26, 2020 | A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor3... |
| CVE-2020-9521 | HIGH | 8.8 | 1.1% | Mar 26, 2020 | An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.0... |
| CVE-2020-9066 | HIGH | 7.8 | 0.6% | Mar 26, 2020 | Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vuln... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now