2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35272 | MEDIUM | 4.8 | 0.6% | Jan 20, 2021 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in t... |
| CVE-2020-35271 | MEDIUM | 4.8 | 0.5% | Jan 20, 2021 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in t... |
| CVE-2020-25683 | MEDIUM | 5.9 | 86.2% | Jan 20, 2021 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is e... |
| CVE-2020-20949 | MEDIUM | 5.9 | 0.9% | Jan 20, 2021 | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for S... |
| CVE-2020-4887 | MEDIUM | 5.5 | 0.3% | Jan 20, 2021 | IBM AIX 7.1, 7.2 and AIX VIOS 3.1 could allow a local user to exploit a vulnerability in the gencore user command to cre... |
| CVE-2020-27852 | MEDIUM | 5.4 | 0.6% | Jan 20, 2021 | A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allo... |
| CVE-2020-27851 | MEDIUM | 5.4 | 0.6% | Jan 20, 2021 | Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketg... |
| CVE-2020-27850 | MEDIUM | 4.8 | 0.6% | Jan 20, 2021 | A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 al... |
| CVE-2020-13134 | MEDIUM | 4.8 | 0.5% | Jan 20, 2021 | Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires a... |
| CVE-2020-13133 | MEDIUM | 6.1 | 0.7% | Jan 20, 2021 | Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires a... |
| CVE-2020-25385 | MEDIUM | 6.1 | 16.2% | Jan 20, 2021 | Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapsho... |
| CVE-2020-19363 | MEDIUM | 6.5 | 3.6% | Jan 20, 2021 | Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directori... |
| CVE-2020-19362 | MEDIUM | 6.1 | 0.7% | Jan 20, 2021 | Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performi... |
| CVE-2020-19361 | MEDIUM | 6.1 | 1.0% | Jan 20, 2021 | Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing mal... |
| CVE-2020-28707 | MEDIUM | 6.1 | 1.4% | Jan 19, 2021 | The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_c... |
| CVE-2020-27269 | MEDIUM | 5.7 | 0.5% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and... |
| CVE-2020-27268 | MEDIUM | 6.5 | 0.5% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin... |
| CVE-2020-27266 | MEDIUM | 6.5 | 0.6% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin... |
| CVE-2020-11997 | MEDIUM | 4.3 | 1.2% | Jan 19, 2021 | Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. I... |
| CVE-2020-27258 | MEDIUM | 6.5 | 0.6% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the com... |
| CVE-2020-27256 | MEDIUM | 6.8 | 0.3% | Jan 19, 2021 | In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu o... |
| CVE-2020-14410 | MEDIUM | 5.4 | 1.7% | Jan 19, 2021 | SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in vi... |
| CVE-2020-8581 | MEDIUM | 6.5 | 0.9% | Jan 19, 2021 | Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authentica... |
| CVE-2020-27276 | MEDIUM | 5.7 | 0.5% | Jan 19, 2021 | SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyD... |
| CVE-2020-27272 | MEDIUM | 5.7 | 0.5% | Jan 19, 2021 | SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now