2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25660 | HIGH | 8.8 | 1.0% | Nov 23, 2020 | A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not ve... |
| CVE-2020-26228 | HIGH | 7.5 | 0.7% | Nov 23, 2020 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user sessio... |
| CVE-2020-24227 | HIGH | 7.5 | 1.4% | Nov 23, 2020 | Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with a... |
| CVE-2020-15246 | HIGH | 7.5 | 1.7% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version... |
| CVE-2020-12351 | HIGH | 8.8 | 7.7% | Nov 23, 2020 | Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a... |
| CVE-2020-7777 | HIGH | 7.2 | 2.0% | Nov 23, 2020 | This affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript... |
| CVE-2020-28421 | HIGH | 7.8 | 0.3% | Nov 23, 2020 | CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that ... |
| CVE-2020-7925 | HIGH | 7.5 | 1.7% | Nov 23, 2020 | Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthent... |
| CVE-2020-27985 | HIGH | 7.8 | 0.5% | Nov 23, 2020 | Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain ro... |
| CVE-2020-28975 | HIGH | 7.5 | 3.4% | Nov 21, 2020 | svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cau... |
| CVE-2020-14258 | HIGH | 7.5 | 1.2% | Nov 21, 2020 | HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A re... |
| CVE-2020-14234 | HIGH | 7.5 | 1.0% | Nov 21, 2020 | HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potent... |
| CVE-2020-14230 | HIGH | 7.5 | 1.2% | Nov 21, 2020 | HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A r... |
| CVE-2020-25185 | HIGH | 8.8 | 2.1% | Nov 21, 2020 | The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to rem... |
| CVE-2020-4005 | HIGH | 7.8 | 0.4% | Nov 20, 2020 | VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a... |
| CVE-2020-4004 | HIGH | 8.2 | 0.4% | Nov 20, 2020 | VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstati... |
| CVE-2020-28845 | HIGH | 7.8 | 1.1% | Nov 20, 2020 | A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious p... |
| CVE-2020-20740 | HIGH | 7.8 | 1.0% | Nov 20, 2020 | PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version(). |
| CVE-2020-26236 | HIGH | 7.5 | 0.9% | Nov 20, 2020 | In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's acc... |
| CVE-2020-19667 | HIGH | 7.8 | 1.6% | Nov 20, 2020 | Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7. |
| CVE-2020-13671 | HIGH | 8.8 | 4.3% | Nov 20, 2020 | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as... |
| CVE-2020-4937 | HIGH | 7.5 | 0.8% | Nov 20, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms ... |
| CVE-2020-4739 | HIGH | 7.8 | 0.4% | Nov 20, 2020 | IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.... |
| CVE-2020-5668 | HIGH | 7.5 | 4.7% | Nov 20, 2020 | Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and ea... |
| CVE-2020-7572 | HIGH | 8.8 | 1.8% | Nov 19, 2020 | A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation W... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now