2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8952 | MEDIUM | 6.1 | 0.7% | Feb 26, 2020 | Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the logout.jsp timeOut parameter. |
| CVE-2020-8951 | MEDIUM | 5.4 | 0.6% | Feb 26, 2020 | Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the C... |
| CVE-2020-9337 | MEDIUM | 6.5 | 0.5% | Feb 26, 2020 | In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request. |
| CVE-2020-9407 | MEDIUM | 5.3 | 0.5% | Feb 26, 2020 | IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COO... |
| CVE-2020-9406 | CRITICAL | 9.8 | 1.2% | Feb 26, 2020 | IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service. |
| CVE-2020-9405 | MEDIUM | 6.1 | 0.6% | Feb 26, 2020 | IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page. |
| CVE-2020-9398 | CRITICAL | 9.8 | 1.3% | Feb 25, 2020 | ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQ... |
| CVE-2020-9394 | HIGH | 8.8 | 0.7% | Feb 25, 2020 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF. |
| CVE-2020-9393 | MEDIUM | 6.1 | 0.9% | Feb 25, 2020 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS. |
| CVE-2020-9379 | MEDIUM | 6.5 | 0.9% | Feb 25, 2020 | The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB4962... |
| CVE-2020-8810 | HIGH | 8.1 | 2.1% | Feb 25, 2020 | An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify ... |
| CVE-2020-8809 | HIGH | 8.1 | 1.0% | Feb 25, 2020 | Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connect... |
| CVE-2020-9391 | MEDIUM | 5.5 | 0.5% | Feb 25, 2020 | An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top by... |
| CVE-2020-9019 | MEDIUM | 6.1 | 1.6% | Feb 25, 2020 | The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Descr... |
| CVE-2020-9018 | MEDIUM | 5.3 | 0.4% | Feb 25, 2020 | LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user. |
| CVE-2020-9008 | MEDIUM | 5.4 | 0.6% | Feb 25, 2020 | Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web... |
| CVE-2020-9335 | MEDIUM | 4.8 | 1.4% | Feb 25, 2020 | Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploita... |
| CVE-2020-9334 | MEDIUM | 5.4 | 0.8% | Feb 25, 2020 | A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitatio... |
| CVE-2020-9017 | HIGH | 8 | 1.1% | Feb 25, 2020 | LiteCart through 2.2.1 allows CSV injection via a customer's profile. |
| CVE-2020-8794 | CRITICAL | 9.8 | 88.5% | Feb 25, 2020 | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult... |
| CVE-2020-8793 | MEDIUM | 4.7 | 0.9% | Feb 25, 2020 | OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combi... |
| CVE-2020-9383 | HIGH | 7.1 | 0.7% | Feb 25, 2020 | An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_re... |
| CVE-2020-8819 | HIGH | 8.1 | 4.5% | Feb 25, 2020 | An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in... |
| CVE-2020-8818 | HIGH | 8.1 | 4.2% | Feb 25, 2020 | An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in t... |
| CVE-2020-9385 | HIGH | 7.5 | 1.6% | Feb 25, 2020 | A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upc... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now