2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9201 | MEDIUM | 6.5 | 0.3% | Dec 24, 2020 | There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software re... |
| CVE-2020-9137 | MEDIUM | 6.7 | 0.2% | Dec 24, 2020 | There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 an... |
| CVE-2020-9119 | MEDIUM | 6.2 | 0.2% | Dec 24, 2020 | There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to p... |
| CVE-2020-35659 | MEDIUM | 6.1 | 0.9% | Dec 24, 2020 | The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indir... |
| CVE-2020-27729 | MEDIUM | 6.1 | 0.6% | Dec 24, 2020 | In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an u... |
| CVE-2020-27727 | MEDIUM | 4.9 | 0.8% | Dec 24, 2020 | On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administra... |
| CVE-2020-27726 | MEDIUM | 6.1 | 0.6% | Dec 24, 2020 | In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-sit... |
| CVE-2020-27722 | MEDIUM | 6.5 | 0.9% | Dec 24, 2020 | In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin doe... |
| CVE-2020-27719 | MEDIUM | 6.1 | 0.6% | Dec 24, 2020 | On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an u... |
| CVE-2020-28190 | MEDIUM | 5.9 | 0.8% | Dec 24, 2020 | TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP... |
| CVE-2020-28185 | MEDIUM | 5.3 | 18.1% | Dec 24, 2020 | User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid us... |
| CVE-2020-28184 | MEDIUM | 5.4 | 0.7% | Dec 24, 2020 | Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitr... |
| CVE-2020-27725 | MEDIUM | 4.3 | 0.8% | Dec 24, 2020 | In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and... |
| CVE-2020-27724 | MEDIUM | 6.5 | 0.9% | Dec 24, 2020 | In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.... |
| CVE-2020-35677 | MEDIUM | 4.8 | 0.3% | Dec 24, 2020 | BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator... |
| CVE-2020-35676 | MEDIUM | 6.1 | 0.7% | Dec 24, 2020 | BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the se... |
| CVE-2020-35669 | MEDIUM | 6.1 | 2.2% | Dec 24, 2020 | An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the ap... |
| CVE-2020-5684 | MEDIUM | 4.8 | 0.3% | Dec 24, 2020 | iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not veri... |
| CVE-2020-2503 | MEDIUM | 5.4 | 0.8% | Dec 24, 2020 | If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in Fi... |
| CVE-2020-35252 | MEDIUM | 6.1 | 1.0% | Dec 23, 2020 | Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registra... |
| CVE-2020-28071 | MEDIUM | 4.8 | 0.6% | Dec 23, 2020 | SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the a... |
| CVE-2020-13969 | MEDIUM | 6.1 | 0.7% | Dec 23, 2020 | CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter... |
| CVE-2020-4642 | MEDIUM | 5.5 | 0.4% | Dec 23, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local atta... |
| CVE-2020-9439 | MEDIUM | 6.1 | 0.8% | Dec 23, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows aut... |
| CVE-2020-6159 | MEDIUM | 6.1 | 0.6% | Dec 23, 2020 | URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scr... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now