2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7243HIGH7.2Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav...
CVE-2020-7242HIGH7.2Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by nav...
CVE-2020-7241HIGH7.5The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/...
CVE-2020-7240HIGH8.8Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS ...
CVE-2020-7215MEDIUM5.5An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 befor...
CVE-2020-7237HIGH8.8Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug L...
CVE-2020-7236MEDIUM6.1UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section).
CVE-2020-7235MEDIUM6.1UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title).
CVE-2020-7234MEDIUM4.8Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wire...
CVE-2020-7233CRITICAL9.8KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Log...
CVE-2020-7232HIGH7.5Evoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and passw...
CVE-2020-7231MEDIUM5.3Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is ...
CVE-2020-7227MEDIUM6.5Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remot...
CVE-2020-7222MEDIUM5.3An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with ...
CVE-2020-7104MEDIUM6.1The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions paramete...
CVE-2020-5397MEDIUM5.3Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that targ...
CVE-2020-6862MEDIUM5.3V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo...
CVE-2020-3940MEDIUM5.9VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability...
CVE-2020-5398HIGH7.5In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, ...
CVE-2020-7039MEDIUM5.6tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands i...
CVE-2020-7048CRITICAL9.1The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any ...
CVE-2020-7047HIGH8.8The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal perm...
CVE-2020-7108MEDIUM5.4The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
CVE-2020-7107MEDIUM6.1The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
CVE-2020-7106MEDIUM6.1Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automatio...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now