2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3933 | MEDIUM | 5.3 | 1.2% | Feb 11, 2020 | TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, allows attackers to enumerate ... |
| CVE-2020-8841 | HIGH | 8.8 | 1.4% | Feb 10, 2020 | An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint i... |
| CVE-2020-8840 | CRITICAL | 9.8 | 26.6% | Feb 10, 2020 | FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apac... |
| CVE-2020-8089 | MEDIUM | 5.4 | 0.6% | Feb 10, 2020 | Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page. |
| CVE-2020-1697 | MEDIUM | 5.4 | 0.8% | Feb 10, 2020 | It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin ... |
| CVE-2020-8825 | MEDIUM | 5.4 | 1.9% | Feb 10, 2020 | index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. |
| CVE-2020-7060 | CRITICAL | 9.1 | 8.9% | Feb 10, 2020 | When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.... |
| CVE-2020-7059 | CRITICAL | 9.1 | 7.4% | Feb 10, 2020 | When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 an... |
| CVE-2020-8823 | MEDIUM | 6.1 | 1.8% | Feb 10, 2020 | htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka cal... |
| CVE-2020-8822 | MEDIUM | 4.8 | 0.6% | Feb 10, 2020 | Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application. |
| CVE-2020-8812 | MEDIUM | 5.4 | 0.6% | Feb 7, 2020 | Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's per... |
| CVE-2020-8811 | MEDIUM | 4.3 | 0.5% | Feb 7, 2020 | ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures. |
| CVE-2020-8808 | HIGH | 7.8 | 0.6% | Feb 7, 2020 | The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged us... |
| CVE-2020-6770 | CRITICAL | 9.8 | 3.6% | Feb 7, 2020 | Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker ... |
| CVE-2020-6768 | HIGH | 7.5 | 1.7% | Feb 7, 2020 | A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated ... |
| CVE-2020-1708 | HIGH | 7 | 0.3% | Feb 7, 2020 | It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3,... |
| CVE-2020-1700 | MEDIUM | 6.5 | 2.5% | Feb 7, 2020 | A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can a... |
| CVE-2020-8796 | CRITICAL | 9.8 | 2.9% | Feb 7, 2020 | Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the serve... |
| CVE-2020-6769 | CRITICAL | 9.1 | 2.2% | Feb 7, 2020 | Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote... |
| CVE-2020-1768 | MEDIUM | 5.4 | 0.7% | Feb 7, 2020 | The external frontend system uses numerous background calls to the backend. Each background request is treated as user a... |
| CVE-2020-8126 | HIGH | 7.8 | 0.5% | Feb 7, 2020 | A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resul... |
| CVE-2020-8788 | MEDIUM | 6.1 | 0.8% | Feb 7, 2020 | Synaptive Medical ClearCanvas ImageServer 3.0 Alpha allows XSS (and HTML injection) via the Default.aspx UserName parame... |
| CVE-2020-8656 | CRITICAL | 9.8 | 84.6% | Feb 7, 2020 | An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe... |
| CVE-2020-8655 | HIGH | 7.8 | 58.1% | Feb 7, 2020 | An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability... |
| CVE-2020-8654 | HIGH | 8.8 | 85.6% | Feb 7, 2020 | An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now