2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5223MEDIUM4.4In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain co...
CVE-2020-7915MEDIUM4.8An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator.
CVE-2020-5221HIGH7.2In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple ...
CVE-2020-7109CRITICAL9.8The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
CVE-2020-7228MEDIUM5.4The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present...
CVE-2020-6960CRITICAL9.8The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT...
CVE-2020-6959CRITICAL9.8The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT...
CVE-2020-7595HIGH7.5xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
CVE-2020-1788MEDIUM5.5Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. ...
CVE-2020-7594HIGH7.2MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitra...
CVE-2020-7040HIGH8.1storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks tha...
CVE-2020-5498Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-6638HIGH7.5Grin through 2.1.1 has Insufficient Validation.
CVE-2020-6849HIGH8.8The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with r...
CVE-2020-1840MEDIUM6HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulner...
CVE-2020-5202MEDIUM5.5apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /u...
CVE-2020-7229CRITICAL9.8An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search en...
CVE-2020-7213HIGH7.5Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date...
CVE-2020-7211HIGH7.5tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
CVE-2020-6857MEDIUM5.5CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT...
CVE-2020-7470MEDIUM4.8Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login wi...
CVE-2020-7246HIGH8.8A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code ...
CVE-2020-7239MEDIUM6.1The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a cha...
CVE-2020-7249MEDIUM4.8SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a success...
CVE-2020-7244HIGH7.2Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now