2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35478 | MEDIUM | 6.1 | 1.4% | Dec 18, 2020 | MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw ... |
| CVE-2020-35477 | MEDIUM | 5.3 | 1.5% | Dec 18, 2020 | MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpag... |
| CVE-2020-35474 | MEDIUM | 6.1 | 1.0% | Dec 18, 2020 | In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of... |
| CVE-2020-27340 | MEDIUM | 6.1 | 0.8% | Dec 18, 2020 | The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized websit... |
| CVE-2020-25612 | MEDIUM | 4.9 | 0.8% | Dec 18, 2020 | The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files... |
| CVE-2020-25611 | MEDIUM | 6.1 | 0.6% | Dec 18, 2020 | The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending ... |
| CVE-2020-25610 | MEDIUM | 5.3 | 0.9% | Dec 18, 2020 | The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insuffi... |
| CVE-2020-25609 | MEDIUM | 5.4 | 0.7% | Dec 18, 2020 | The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scr... |
| CVE-2020-25606 | MEDIUM | 6.1 | 0.6% | Dec 18, 2020 | The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary c... |
| CVE-2020-13528 | MEDIUM | 5.3 | 2.9% | Dec 18, 2020 | An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3... |
| CVE-2020-13527 | MEDIUM | 4.5 | 0.6% | Dec 18, 2020 | An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0... |
| CVE-2020-13518 | MEDIUM | 6.5 | 0.5% | Dec 18, 2020 | An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c402084 functionality of NZXT CAM 4.8.0.... |
| CVE-2020-13517 | MEDIUM | 5.5 | 0.5% | Dec 18, 2020 | An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0.... |
| CVE-2020-13516 | MEDIUM | 6.5 | 0.5% | Dec 18, 2020 | An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406144 functionality of NZXT CAM 4.8.0.... |
| CVE-2020-13511 | MEDIUM | 6.5 | 0.5% | Dec 18, 2020 | An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT ... |
| CVE-2020-13510 | MEDIUM | 6.5 | 0.4% | Dec 18, 2020 | An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT ... |
| CVE-2020-13509 | MEDIUM | 6.5 | 0.5% | Dec 18, 2020 | An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT ... |
| CVE-2020-20142 | MEDIUM | 6.1 | 1.6% | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table &... |
| CVE-2020-20141 | MEDIUM | 6.1 | 1.6% | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Tab... |
| CVE-2020-20140 | MEDIUM | 6.1 | 1.6% | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Cha... |
| CVE-2020-20139 | MEDIUM | 6.1 | 1.6% | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table ... |
| CVE-2020-20138 | MEDIUM | 6.1 | 3.3% | Dec 17, 2020 | Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4. |
| CVE-2020-12521 | MEDIUM | 6.5 | 0.5% | Dec 17, 2020 | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high... |
| CVE-2020-12518 | MEDIUM | 5.5 | 0.7% | Dec 17, 2020 | On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by readin... |
| CVE-2020-8462 | MEDIUM | 4.8 | 1.1% | Dec 17, 2020 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now