2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7779 | HIGH | 7.5 | 1.7% | Nov 26, 2020 | All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted in... |
| CVE-2020-7778 | HIGH | 7.3 | 2.4% | Nov 26, 2020 | This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an ... |
| CVE-2020-27255 | HIGH | 7.5 | 3.2% | Nov 26, 2020 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a re... |
| CVE-2020-27253 | HIGH | 7.5 | 1.6% | Nov 26, 2020 | A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could ... |
| CVE-2020-29074 | HIGH | 8.8 | 1.7% | Nov 25, 2020 | scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. |
| CVE-2020-14190 | HIGH | 7.5 | 1.2% | Nov 25, 2020 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-suppl... |
| CVE-2020-14191 | HIGH | 7.5 | 1.2% | Nov 25, 2020 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a De... |
| CVE-2020-26243 | HIGH | 7.5 | 2.6% | Nov 25, 2020 | Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding speci... |
| CVE-2020-26242 | HIGH | 7.5 | 1.5% | Nov 25, 2020 | Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.18, t... |
| CVE-2020-26241 | HIGH | 7.1 | 1.1% | Nov 25, 2020 | Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerabilit... |
| CVE-2020-26240 | HIGH | 7.5 | 1.6% | Nov 25, 2020 | Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation ... |
| CVE-2020-26238 | HIGH | 8.1 | 4.2% | Nov 25, 2020 | Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In c... |
| CVE-2020-26237 | HIGH | 8.7 | 1.3% | Nov 24, 2020 | Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerabl... |
| CVE-2020-29063 | HIGH | 7.5 | 0.5% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-29057 | HIGH | 7.5 | 1.9% | Nov 24, 2020 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716... |
| CVE-2020-25654 | HIGH | 7.2 | 2.0% | Nov 24, 2020 | An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group c... |
| CVE-2020-28331 | HIGH | 7.5 | 1.7% | Nov 24, 2020 | Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-... |
| CVE-2020-13620 | HIGH | 8.8 | 0.5% | Nov 24, 2020 | Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading ... |
| CVE-2020-29040 | HIGH | 8.8 | 0.4% | Nov 24, 2020 | An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corrup... |
| CVE-2020-4002 | HIGH | 7.2 | 1.6% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 handles system parameter... |
| CVE-2020-4000 | HIGH | 8.8 | 43.0% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing fil... |
| CVE-2020-3985 | HIGH | 8.8 | 1.4% | Nov 24, 2020 | The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 allows an access to set arbitrary authorization... |
| CVE-2020-5674 | HIGH | 7.8 | 0.3% | Nov 24, 2020 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privil... |
| CVE-2020-26890 | HIGH | 7.5 | 3.0% | Nov 24, 2020 | Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.ro... |
| CVE-2020-25696 | HIGH | 7.5 | 2.6% | Nov 23, 2020 | A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, befo... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now