2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35650 | MEDIUM | 6.1 | 0.8% | Dec 23, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remo... |
| CVE-2020-35584 | MEDIUM | 5.9 | 0.8% | Dec 23, 2020 | In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser ... |
| CVE-2020-25192 | MEDIUM | 5.3 | 0.9% | Dec 23, 2020 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be dis... |
| CVE-2020-35658 | MEDIUM | 5.3 | 0.5% | Dec 23, 2020 | SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted. |
| CVE-2020-27336 | MEDIUM | 5.3 | 1.7% | Dec 22, 2020 | An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a p... |
| CVE-2020-14874 | MEDIUM | 4.7 | 0.8% | Dec 22, 2020 | Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily... |
| CVE-2020-14270 | MEDIUM | 5.3 | 0.9% | Dec 22, 2020 | HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handli... |
| CVE-2020-35609 | MEDIUM | 5.5 | 1.3% | Dec 22, 2020 | A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequ... |
| CVE-2020-24578 | MEDIUM | 6.5 | 1.8% | Dec 22, 2020 | An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured F... |
| CVE-2020-35624 | MEDIUM | 5.3 | 1.0% | Dec 21, 2020 | An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a ful... |
| CVE-2020-35622 | MEDIUM | 6.1 | 0.7% | Dec 21, 2020 | An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap:... |
| CVE-2020-26277 | MEDIUM | 6.1 | 1.2% | Dec 21, 2020 | DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a ... |
| CVE-2020-4843 | MEDIUM | 4.3 | 0.5% | Dec 21, 2020 | IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authen... |
| CVE-2020-4842 | MEDIUM | 4.9 | 1.1% | Dec 21, 2020 | IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical ... |
| CVE-2020-4841 | MEDIUM | 5.9 | 1.2% | Dec 21, 2020 | IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to ... |
| CVE-2020-4840 | MEDIUM | 6.1 | 0.9% | Dec 21, 2020 | IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack... |
| CVE-2020-4794 | MEDIUM | 5.4 | 0.8% | Dec 21, 2020 | IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM... |
| CVE-2020-4757 | MEDIUM | 6.4 | 1.3% | Dec 21, 2020 | IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerab... |
| CVE-2020-4555 | MEDIUM | 5.4 | 0.8% | Dec 21, 2020 | IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenti... |
| CVE-2020-26422 | MEDIUM | 5.3 | 4.7% | Dec 21, 2020 | Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted c... |
| CVE-2020-26275 | MEDIUM | 6.1 | 1.4% | Dec 21, 2020 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications ... |
| CVE-2020-25860 | MEDIUM | 6.6 | 1.4% | Dec 21, 2020 | The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerab... |
| CVE-2020-14225 | MEDIUM | 6.5 | 1.3% | Dec 21, 2020 | HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote una... |
| CVE-2020-35497 | MEDIUM | 6.5 | 0.8% | Dec 21, 2020 | A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal informat... |
| CVE-2020-3999 | MEDIUM | 6.5 | 0.3% | Dec 21, 2020 | VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now