2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7243 | HIGH | 7.2 | 4.2% | Jan 20, 2020 | Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav... |
| CVE-2020-7242 | HIGH | 7.2 | 4.4% | Jan 20, 2020 | Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav... |
| CVE-2020-7241 | HIGH | 7.5 | 2.4% | Jan 20, 2020 | The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/... |
| CVE-2020-7240 | HIGH | 8.8 | 2.4% | Jan 20, 2020 | Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS ... |
| CVE-2020-7215 | MEDIUM | 5.5 | 0.3% | Jan 20, 2020 | An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 befor... |
| CVE-2020-7237 | HIGH | 8.8 | 36.8% | Jan 20, 2020 | Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug L... |
| CVE-2020-7236 | MEDIUM | 6.1 | 0.7% | Jan 19, 2020 | UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section). |
| CVE-2020-7235 | MEDIUM | 6.1 | 0.7% | Jan 19, 2020 | UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title). |
| CVE-2020-7234 | MEDIUM | 4.8 | 0.6% | Jan 19, 2020 | Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wire... |
| CVE-2020-7233 | CRITICAL | 9.8 | 1.7% | Jan 19, 2020 | KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Log... |
| CVE-2020-7232 | HIGH | 7.5 | 1.5% | Jan 19, 2020 | Evoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and passw... |
| CVE-2020-7231 | MEDIUM | 5.3 | 1.0% | Jan 19, 2020 | Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is ... |
| CVE-2020-7227 | MEDIUM | 6.5 | 1.3% | Jan 18, 2020 | Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remot... |
| CVE-2020-7222 | MEDIUM | 5.3 | 1.3% | Jan 18, 2020 | An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with ... |
| CVE-2020-7104 | MEDIUM | 6.1 | 1.6% | Jan 17, 2020 | The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions paramete... |
| CVE-2020-5397 | MEDIUM | 5.3 | 2.4% | Jan 17, 2020 | Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that targ... |
| CVE-2020-6862 | MEDIUM | 5.3 | 6.3% | Jan 17, 2020 | V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo... |
| CVE-2020-3940 | MEDIUM | 5.9 | 0.8% | Jan 17, 2020 | VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability... |
| CVE-2020-5398 | HIGH | 7.5 | 88.1% | Jan 17, 2020 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, ... |
| CVE-2020-7039 | MEDIUM | 5.6 | 3.6% | Jan 16, 2020 | tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands i... |
| CVE-2020-7048 | CRITICAL | 9.1 | 22.9% | Jan 16, 2020 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any ... |
| CVE-2020-7047 | HIGH | 8.8 | 2.5% | Jan 16, 2020 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal perm... |
| CVE-2020-7108 | MEDIUM | 5.4 | 3.5% | Jan 16, 2020 | The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. |
| CVE-2020-7107 | MEDIUM | 6.1 | 2.2% | Jan 16, 2020 | The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php. |
| CVE-2020-7106 | MEDIUM | 6.1 | 2.1% | Jan 16, 2020 | Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automatio... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now