2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13675 | CRITICAL | 9.8 | 1.2% | Feb 11, 2022 | Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all... |
| CVE-2020-13674 | MEDIUM | 6.5 | 0.4% | Feb 11, 2022 | The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under som... |
| CVE-2020-13673 | MEDIUM | 6.1 | 0.3% | Feb 11, 2022 | The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the f... |
| CVE-2020-13672 | MEDIUM | 6.1 | 0.7% | Feb 11, 2022 | Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting... |
| CVE-2020-13670 | HIGH | 7.5 | 1.1% | Feb 11, 2022 | Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadat... |
| CVE-2020-13669 | MEDIUM | 6.1 | 0.6% | Feb 11, 2022 | Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: D... |
| CVE-2020-13668 | MEDIUM | 6.1 | 0.7% | Feb 11, 2022 | Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected... |
| CVE-2020-7534 | HIGH | 8.8 | 0.4% | Feb 4, 2022 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sen... |
| CVE-2020-12966 | MEDIUM | 5.5 | 0.3% | Feb 4, 2022 | AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypt... |
| CVE-2020-12965 | HIGH | 7.5 | 2.4% | Feb 4, 2022 | When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using onl... |
| CVE-2020-12891 | HIGH | 7.8 | 0.3% | Feb 4, 2022 | AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop i... |
| CVE-2020-5953 | HIGH | 7.5 | 0.3% | Feb 3, 2022 | A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI h... |
| CVE-2020-26208 | MEDIUM | 6.1 | 0.9% | Feb 2, 2022 | JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images fro... |
| CVE-2020-8562 | LOW | 3.1 | 1.1% | Feb 1, 2022 | As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessin... |
| CVE-2020-36064 | CRITICAL | 9.8 | 1.5% | Jan 31, 2022 | Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attacker... |
| CVE-2020-36056 | MEDIUM | 5.4 | 0.5% | Jan 31, 2022 | Beetel 777VR1-DI Hardware Version REV.1.01 Firmware Version V01.00.09_55 was discovered to contain a cross-site scriptin... |
| CVE-2020-25905 | CRITICAL | 9.8 | 1.7% | Jan 28, 2022 | An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1... |
| CVE-2020-28885 | HIGH | 7.2 | 2.1% | Jan 28, 2022 | Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje... |
| CVE-2020-28884 | HIGH | 7.2 | 2.0% | Jan 28, 2022 | Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje... |
| CVE-2020-17383 | CRITICAL | 9.8 | 4.3% | Jan 24, 2022 | A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root l... |
| CVE-2020-4879 | CRITICAL | 9.8 | 1.5% | Jan 21, 2022 | IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused b... |
| CVE-2020-4877 | CRITICAL | 9.8 | 0.9% | Jan 21, 2022 | IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public field... |
| CVE-2020-4876 | HIGH | 8.2 | 1.7% | Jan 21, 2022 | IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2020-4875 | HIGH | 8.2 | 1.7% | Jan 21, 2022 | IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2020-19861 | HIGH | 7.5 | 1.5% | Jan 21, 2022 | When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now