2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10255 | CRITICAL | 9 | 2.5% | Mar 10, 2020 | Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations aga... |
| CVE-2020-4162 | MEDIUM | 5.4 | 0.6% | Mar 10, 2020 | IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2020-10251 | MEDIUM | 5.5 | 1.5% | Mar 10, 2020 | In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c.... |
| CVE-2020-10257 | CRITICAL | 9.8 | 8.9% | Mar 10, 2020 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST... |
| CVE-2020-5342 | HIGH | 7.8 | 0.4% | Mar 9, 2020 | Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authe... |
| CVE-2020-9758 | CRITICAL | 9.6 | 2.5% | Mar 9, 2020 | An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the ... |
| CVE-2020-10250 | CRITICAL | 9.8 | 2.6% | Mar 9, 2020 | BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG... |
| CVE-2020-10249 | MEDIUM | 5.3 | 1.0% | Mar 9, 2020 | BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3. |
| CVE-2020-10248 | HIGH | 7.5 | 1.4% | Mar 9, 2020 | BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3. |
| CVE-2020-10247 | MEDIUM | 6.1 | 0.8% | Mar 9, 2020 | MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_... |
| CVE-2020-10246 | MEDIUM | 6.1 | 0.8% | Mar 9, 2020 | MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp. |
| CVE-2020-10244 | HIGH | 7.5 | 0.7% | Mar 9, 2020 | JPaseto before 0.3.0 generates weak hashes when using v2.local tokens. |
| CVE-2020-10192 | MEDIUM | 6.1 | 0.8% | Mar 9, 2020 | An issue was discovered in Munkireport before 5.3.0.3923. An unauthenticated actor can send a custom XSS payload through... |
| CVE-2020-10191 | MEDIUM | 5.4 | 0.6% | Mar 9, 2020 | An issue was discovered in MunkiReport before 5.3.0. An authenticated actor can send a custom XSS payload through the /m... |
| CVE-2020-10190 | HIGH | 8.8 | 1.2% | Mar 9, 2020 | An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tab... |
| CVE-2020-8987 | HIGH | 7.4 | 0.5% | Mar 9, 2020 | Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate... |
| CVE-2020-4084 | MEDIUM | 5.4 | 0.5% | Mar 9, 2020 | HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2020-9517 | MEDIUM | 5.4 | 0.5% | Mar 9, 2020 | There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Co... |
| CVE-2020-9386 | MEDIUM | 4.3 | 1.0% | Mar 9, 2020 | In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed t... |
| CVE-2020-5256 | HIGH | 8.8 | 2.0% | Mar 9, 2020 | BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, ... |
| CVE-2020-2159 | HIGH | 8.8 | 2.0% | Mar 9, 2020 | Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands... |
| CVE-2020-2158 | HIGH | 8.8 | 2.9% | Mar 9, 2020 | Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary typ... |
| CVE-2020-2157 | MEDIUM | 4.3 | 0.5% | Mar 9, 2020 | Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configurat... |
| CVE-2020-2156 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration ... |
| CVE-2020-2155 | MEDIUM | 5.3 | 0.6% | Mar 9, 2020 | Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now