2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25698 | HIGH | 7.5 | 1.9% | Nov 19, 2020 | Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing cou... |
| CVE-2020-4701 | HIGH | 7.8 | 0.5% | Nov 19, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflo... |
| CVE-2020-28054 | HIGH | 7.5 | 2.0% | Nov 19, 2020 | JamoDat TSMManager Collector version up to 6.5.0.21 is vulnerable to an Authorization Bypass because the Collector compo... |
| CVE-2020-8279 | HIGH | 7.4 | 0.6% | Nov 19, 2020 | Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-mid... |
| CVE-2020-8277 | HIGH | 7.5 | 54.2% | Nov 19, 2020 | A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial... |
| CVE-2020-13359 | HIGH | 7.6 | 0.8% | Nov 19, 2020 | The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malici... |
| CVE-2020-13356 | HIGH | 8.2 | 1.8% | Nov 19, 2020 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request cou... |
| CVE-2020-13355 | HIGH | 8.1 | 1.7% | Nov 19, 2020 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS... |
| CVE-2020-12593 | HIGH | 7.5 | 2.0% | Nov 18, 2020 | Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a ... |
| CVE-2020-26226 | HIGH | 8.1 | 1.4% | Nov 18, 2020 | In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` c... |
| CVE-2020-15301 | HIGH | 7.8 | 0.8% | Nov 18, 2020 | SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Lead... |
| CVE-2020-28581 | HIGH | 7.2 | 44.5% | Nov 18, 2020 | A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 coul... |
| CVE-2020-28580 | HIGH | 7.2 | 44.5% | Nov 18, 2020 | A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could a... |
| CVE-2020-28579 | HIGH | 8.8 | 49.3% | Nov 18, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote att... |
| CVE-2020-28574 | HIGH | 7.5 | 2.8% | Nov 18, 2020 | A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Securit... |
| CVE-2020-28572 | HIGH | 7.8 | 0.4% | Nov 18, 2020 | A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the... |
| CVE-2020-27697 | HIGH | 7.8 | 0.6% | Nov 18, 2020 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placin... |
| CVE-2020-27696 | HIGH | 7.8 | 0.5% | Nov 18, 2020 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placin... |
| CVE-2020-27695 | HIGH | 7.8 | 0.5% | Nov 18, 2020 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placin... |
| CVE-2020-3392 | HIGH | 7.5 | 1.5% | Nov 18, 2020 | A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to ... |
| CVE-2020-3367 | HIGH | 7.8 | 0.8% | Nov 18, 2020 | A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Secu... |
| CVE-2020-26076 | HIGH | 7.5 | 1.3% | Nov 18, 2020 | A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensit... |
| CVE-2020-26075 | HIGH | 8.8 | 1.6% | Nov 18, 2020 | A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker ... |
| CVE-2020-26072 | HIGH | 8.7 | 1.0% | Nov 18, 2020 | A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker ... |
| CVE-2020-28367 | HIGH | 7.5 | 2.4% | Nov 18, 2020 | Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now