2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5223 | MEDIUM | 4.4 | 0.7% | Jan 23, 2020 | In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain co... |
| CVE-2020-7915 | MEDIUM | 4.8 | 0.7% | Jan 22, 2020 | An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator. |
| CVE-2020-5221 | HIGH | 7.2 | 1.2% | Jan 22, 2020 | In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple ... |
| CVE-2020-7109 | CRITICAL | 9.8 | 1.7% | Jan 22, 2020 | The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. |
| CVE-2020-7228 | MEDIUM | 5.4 | 1.0% | Jan 22, 2020 | The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present... |
| CVE-2020-6960 | CRITICAL | 9.8 | 1.1% | Jan 22, 2020 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT... |
| CVE-2020-6959 | CRITICAL | 9.8 | 2.2% | Jan 22, 2020 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT... |
| CVE-2020-7595 | HIGH | 7.5 | 7.8% | Jan 21, 2020 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. |
| CVE-2020-1788 | MEDIUM | 5.5 | 0.6% | Jan 21, 2020 | Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. ... |
| CVE-2020-7594 | HIGH | 7.2 | 2.5% | Jan 21, 2020 | MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitra... |
| CVE-2020-7040 | HIGH | 8.1 | 2.9% | Jan 21, 2020 | storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks tha... |
| CVE-2020-5498 | — | — | — | Jan 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-6638 | HIGH | 7.5 | 1.3% | Jan 21, 2020 | Grin through 2.1.1 has Insufficient Validation. |
| CVE-2020-6849 | HIGH | 8.8 | 1.3% | Jan 21, 2020 | The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with r... |
| CVE-2020-1840 | MEDIUM | 6 | 0.2% | Jan 21, 2020 | HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulner... |
| CVE-2020-5202 | MEDIUM | 5.5 | 0.5% | Jan 21, 2020 | apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /u... |
| CVE-2020-7229 | CRITICAL | 9.8 | 1.5% | Jan 21, 2020 | An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search en... |
| CVE-2020-7213 | HIGH | 7.5 | 1.1% | Jan 21, 2020 | Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date... |
| CVE-2020-7211 | HIGH | 7.5 | 4.1% | Jan 21, 2020 | tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. |
| CVE-2020-6857 | MEDIUM | 5.5 | 1.0% | Jan 21, 2020 | CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT... |
| CVE-2020-7470 | MEDIUM | 4.8 | 0.6% | Jan 21, 2020 | Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login wi... |
| CVE-2020-7246 | HIGH | 8.8 | 83.2% | Jan 21, 2020 | A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code ... |
| CVE-2020-7239 | MEDIUM | 6.1 | 1.4% | Jan 21, 2020 | The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a cha... |
| CVE-2020-7249 | MEDIUM | 4.8 | 0.6% | Jan 21, 2020 | SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a success... |
| CVE-2020-7244 | HIGH | 7.2 | 4.2% | Jan 20, 2020 | Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now