2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27270 | MEDIUM | 5.7 | 0.3% | Jan 19, 2021 | SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDa... |
| CVE-2020-4873 | MEDIUM | 5.3 | 1.0% | Jan 19, 2021 | IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS poli... |
| CVE-2020-4871 | MEDIUM | 5.5 | 0.3% | Jan 19, 2021 | IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-... |
| CVE-2020-28481 | MEDIUM | 4.3 | 0.7% | Jan 19, 2021 | The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whi... |
| CVE-2020-23522 | MEDIUM | 6.8 | 2.0% | Jan 19, 2021 | Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter. |
| CVE-2020-20950 | MEDIUM | 5.9 | 0.9% | Jan 19, 2021 | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 201... |
| CVE-2020-29450 | MEDIUM | 6.5 | 2.2% | Jan 19, 2021 | Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's avai... |
| CVE-2020-36192 | MEDIUM | 5.3 | 1.0% | Jan 18, 2021 | An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the S... |
| CVE-2020-7343 | MEDIUM | 5.5 | 0.4% | Jan 18, 2021 | Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee p... |
| CVE-2020-28473 | MEDIUM | 6.8 | 1.8% | Jan 18, 2021 | The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cl... |
| CVE-2020-29446 | MEDIUM | 5.3 | 1.1% | Jan 18, 2021 | Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Ob... |
| CVE-2020-15864 | MEDIUM | 6.1 | 0.7% | Jan 17, 2021 | An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a UR... |
| CVE-2020-16255 | MEDIUM | 6.1 | 0.8% | Jan 15, 2021 | ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.' |
| CVE-2020-35748 | MEDIUM | 5.4 | 0.9% | Jan 15, 2021 | Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37... |
| CVE-2020-26414 | MEDIUM | 6.5 | 1.5% | Jan 15, 2021 | An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is wr... |
| CVE-2020-35582 | MEDIUM | 5.4 | 1.3% | Jan 15, 2021 | A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitr... |
| CVE-2020-35581 | MEDIUM | 5.4 | 1.3% | Jan 15, 2021 | A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitr... |
| CVE-2020-27219 | MEDIUM | 6.1 | 0.8% | Jan 14, 2021 | In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API... |
| CVE-2020-16046 | MEDIUM | 6.1 | 0.8% | Jan 14, 2021 | Script injection in iOSWeb in Google Chrome on iOS prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary... |
| CVE-2020-6777 | MEDIUM | 4.8 | 0.6% | Jan 14, 2021 | A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAE... |
| CVE-2020-29587 | MEDIUM | 5.4 | 0.7% | Jan 14, 2021 | SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap m... |
| CVE-2020-29019 | MEDIUM | 5.3 | 2.1% | Jan 14, 2021 | A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote,... |
| CVE-2020-27368 | MEDIUM | 5.5 | 0.5% | Jan 14, 2021 | Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /ic... |
| CVE-2020-26733 | MEDIUM | 5.4 | 0.7% | Jan 14, 2021 | Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 ... |
| CVE-2020-28470 | MEDIUM | 6.1 | 0.8% | Jan 14, 2021 | This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() funct... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now