2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10788 | CRITICAL | 9.1 | 1.6% | Mar 25, 2020 | openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API... |
| CVE-2020-10791 | MEDIUM | 6.5 | 1.2% | Mar 25, 2020 | app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authe... |
| CVE-2020-10790 | MEDIUM | 5.4 | 0.9% | Mar 25, 2020 | openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. |
| CVE-2020-10789 | CRITICAL | 9.8 | 1.9% | Mar 25, 2020 | openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell met... |
| CVE-2020-5561 | CRITICAL | 9.8 | 2.3% | Mar 25, 2020 | Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
| CVE-2020-5560 | CRITICAL | 9.8 | 2.3% | Mar 25, 2020 | WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unsp... |
| CVE-2020-5559 | MEDIUM | 6.1 | 0.8% | Mar 25, 2020 | Cross-site scripting vulnerability in WL-Enq 1.11 and 1.12 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2020-5558 | HIGH | 8.8 | 2.1% | Mar 25, 2020 | CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. |
| CVE-2020-5557 | MEDIUM | 6.1 | 0.8% | Mar 25, 2020 | Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via ... |
| CVE-2020-5556 | CRITICAL | 9.8 | 2.3% | Mar 25, 2020 | Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified v... |
| CVE-2020-5555 | CRITICAL | 9.1 | 1.3% | Mar 25, 2020 | Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the ... |
| CVE-2020-5554 | CRITICAL | 9.1 | 1.9% | Mar 25, 2020 | Directory traversal vulnerability in Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and w... |
| CVE-2020-5553 | CRITICAL | 9.8 | 2.3% | Mar 25, 2020 | mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors. |
| CVE-2020-5552 | MEDIUM | 6.1 | 0.8% | Mar 25, 2020 | Cross-site scripting vulnerability in mailform version 1.04 allows remote attackers to inject arbitrary web script or HT... |
| CVE-2020-5261 | MEDIUM | 6.8 | 1.2% | Mar 25, 2020 | Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5... |
| CVE-2020-6816 | MEDIUM | 6.1 | 1.3% | Mar 24, 2020 | In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted an... |
| CVE-2020-6802 | MEDIUM | 6.1 | 1.7% | Mar 24, 2020 | In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allo... |
| CVE-2020-10942 | MEDIUM | 5.3 | 1.0% | Mar 24, 2020 | In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which mi... |
| CVE-2020-8986 | CRITICAL | 9.8 | 1.5% | Mar 24, 2020 | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cook... |
| CVE-2020-8985 | HIGH | 8.8 | 0.5% | Mar 24, 2020 | ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality. |
| CVE-2020-8984 | HIGH | 7.5 | 0.5% | Mar 24, 2020 | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header. |
| CVE-2020-7007 | CRITICAL | 9.8 | 2.7% | Mar 24, 2020 | In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, ... |
| CVE-2020-7001 | HIGH | 7.5 | 0.8% | Mar 24, 2020 | In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which... |
| CVE-2020-6997 | HIGH | 7.5 | 0.8% | Mar 24, 2020 | In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications... |
| CVE-2020-6991 | CRITICAL | 9.8 | 1.3% | Mar 24, 2020 | In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now