2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29193 | MEDIUM | 6.8 | 0.4% | Dec 28, 2020 | Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboa... |
| CVE-2020-28096 | MEDIUM | 6.8 | 0.5% | Dec 28, 2020 | FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password. |
| CVE-2020-35738 | MEDIUM | 6.1 | 1.2% | Dec 28, 2020 | WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a mallo... |
| CVE-2020-29156 | MEDIUM | 5.3 | 4.0% | Dec 27, 2020 | The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the... |
| CVE-2020-29250 | MEDIUM | 6.1 | 0.7% | Dec 27, 2020 | CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php. |
| CVE-2020-29249 | MEDIUM | 6.1 | 0.7% | Dec 27, 2020 | CXUUCMS V3 allows class="layui-input" XSS. |
| CVE-2020-29204 | MEDIUM | 6.1 | 0.9% | Dec 27, 2020 | XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/j... |
| CVE-2020-35678 | MEDIUM | 6.1 | 1.4% | Dec 27, 2020 | Autobahn|Python before 20.12.3 allows redirect header injection. |
| CVE-2020-28759 | MEDIUM | 5.5 | 0.7% | Dec 26, 2020 | The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don'... |
| CVE-2020-35437 | MEDIUM | 6.1 | 3.0% | Dec 26, 2020 | Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the... |
| CVE-2020-35349 | MEDIUM | 4.8 | 0.6% | Dec 26, 2020 | Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page). |
| CVE-2020-35347 | MEDIUM | 6.5 | 0.4% | Dec 26, 2020 | CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add. |
| CVE-2020-35346 | MEDIUM | 4.8 | 0.7% | Dec 26, 2020 | CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script ... |
| CVE-2020-20412 | MEDIUM | 6.5 | 1.0% | Dec 26, 2020 | lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds ... |
| CVE-2020-29385 | MEDIUM | 5.5 | 1.5% | Dec 26, 2020 | GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write... |
| CVE-2020-29172 | MEDIUM | 6.1 | 0.9% | Dec 26, 2020 | A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via... |
| CVE-2020-27515 | MEDIUM | 6.1 | 1.3% | Dec 26, 2020 | A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script o... |
| CVE-2020-35710 | MEDIUM | 5.3 | 1.7% | Dec 25, 2020 | Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submissi... |
| CVE-2020-35709 | MEDIUM | 4.9 | 1.1% | Dec 25, 2020 | bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../me... |
| CVE-2020-35707 | MEDIUM | 5.4 | 0.6% | Dec 25, 2020 | Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen. |
| CVE-2020-35706 | MEDIUM | 5.4 | 0.6% | Dec 25, 2020 | Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen. |
| CVE-2020-35705 | MEDIUM | 5.4 | 0.6% | Dec 25, 2020 | Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen. |
| CVE-2020-35704 | MEDIUM | 5.4 | 0.6% | Dec 25, 2020 | Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen. |
| CVE-2020-29247 | MEDIUM | 4.8 | 1.1% | Dec 24, 2020 | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in ... |
| CVE-2020-9202 | MEDIUM | 4.4 | 0.2% | Dec 24, 2020 | There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now