2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6954 | MEDIUM | 6.5 | 1.0% | Jan 13, 2020 | An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Conne... |
| CVE-2020-6832 | MEDIUM | 5.3 | 0.9% | Jan 13, 2020 | An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was... |
| CVE-2020-5197 | MEDIUM | 4.3 | 0.7% | Jan 13, 2020 | An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrec... |
| CVE-2020-6949 | HIGH | 8.8 | 1.3% | Jan 13, 2020 | A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can ... |
| CVE-2020-6948 | CRITICAL | 9.8 | 3.6% | Jan 13, 2020 | A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a... |
| CVE-2020-5390 | HIGH | 7.5 | 1.2% | Jan 13, 2020 | PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is ef... |
| CVE-2020-5195 | MEDIUM | 6.1 | 1.2% | Jan 13, 2020 | Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacke... |
| CVE-2020-6859 | MEDIUM | 5.3 | 2.2% | Jan 13, 2020 | Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin... |
| CVE-2020-6860 | HIGH | 8.8 | 1.7% | Jan 13, 2020 | libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header mess... |
| CVE-2020-6851 | HIGH | 7.5 | 4.9% | Jan 13, 2020 | OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack ... |
| CVE-2020-6848 | MEDIUM | 6.1 | 0.7% | Jan 13, 2020 | Axper Vision II 4 devices allow XSS via the DEVICE_NAME (aka Device Name) parameter to the configWebParams.cgi URI. |
| CVE-2020-6847 | MEDIUM | 5.4 | 0.9% | Jan 11, 2020 | OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a me... |
| CVE-2020-6840 | CRITICAL | 9.8 | 1.5% | Jan 11, 2020 | In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c. |
| CVE-2020-6839 | CRITICAL | 9.8 | 1.4% | Jan 11, 2020 | In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c. |
| CVE-2020-6838 | CRITICAL | 9.8 | 1.5% | Jan 11, 2020 | In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c. |
| CVE-2020-6836 | CRITICAL | 9.8 | 2.1% | Jan 11, 2020 | grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injectio... |
| CVE-2020-6377 | HIGH | 8.8 | 1.5% | Jan 10, 2020 | Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap co... |
| CVE-2020-6835 | CRITICAL | 9.8 | 2.0% | Jan 10, 2020 | An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking. |
| CVE-2020-6162 | CRITICAL | 9.1 | 1.7% | Jan 10, 2020 | An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitia... |
| CVE-2020-1767 | MEDIUM | 4.3 | 1.2% | Jan 10, 2020 | Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely a... |
| CVE-2020-1766 | MEDIUM | 6.1 | 1.3% | Jan 10, 2020 | Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents brow... |
| CVE-2020-1765 | MEDIUM | 5.3 | 1.5% | Jan 10, 2020 | An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, A... |
| CVE-2020-6758 | MEDIUM | 6.1 | 0.8% | Jan 9, 2020 | A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI... |
| CVE-2020-6757 | HIGH | 8.8 | 1.4% | Jan 9, 2020 | contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers t... |
| CVE-2020-6756 | CRITICAL | 9.8 | 10.6% | Jan 9, 2020 | languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now