2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13497 | MEDIUM | 5.5 | 1.2% | Dec 2, 2020 | An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra... |
| CVE-2020-13496 | MEDIUM | 6.5 | 1.7% | Dec 2, 2020 | An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially cra... |
| CVE-2020-13494 | MEDIUM | 5.5 | 1.2% | Dec 2, 2020 | A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files.... |
| CVE-2020-29240 | MEDIUM | 4.8 | 1.7% | Dec 2, 2020 | Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of t... |
| CVE-2020-29239 | MEDIUM | 6.1 | 0.5% | Dec 2, 2020 | Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result i... |
| CVE-2020-25266 | MEDIUM | 5.5 | 0.3% | Dec 2, 2020 | AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it w... |
| CVE-2020-25265 | MEDIUM | 6.5 | 1.9% | Dec 2, 2020 | AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by provid... |
| CVE-2020-13956 | MEDIUM | 5.3 | 8.7% | Dec 2, 2020 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request U... |
| CVE-2020-14369 | MEDIUM | 6.3 | 0.3% | Dec 2, 2020 | This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to ... |
| CVE-2020-29456 | MEDIUM | 6.1 | 1.5% | Dec 2, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrar... |
| CVE-2020-29454 | MEDIUM | 4.3 | 0.9% | Dec 2, 2020 | Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Ap... |
| CVE-2020-4102 | MEDIUM | 6.7 | 0.3% | Dec 2, 2020 | HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successfu... |
| CVE-2020-27816 | MEDIUM | 6.1 | 0.6% | Dec 2, 2020 | The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it i... |
| CVE-2020-25704 | MEDIUM | 5.5 | 0.3% | Dec 2, 2020 | A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET... |
| CVE-2020-25656 | MEDIUM | 4.1 | 0.4% | Dec 2, 2020 | A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKB... |
| CVE-2020-14383 | MEDIUM | 6.5 | 2.2% | Dec 2, 2020 | A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC s... |
| CVE-2020-26250 | MEDIUM | 6.3 | 1.1% | Dec 1, 2020 | OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the ... |
| CVE-2020-28583 | MEDIUM | 5.3 | 3.2% | Dec 1, 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo... |
| CVE-2020-28582 | MEDIUM | 5.3 | 3.2% | Dec 1, 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo... |
| CVE-2020-28577 | MEDIUM | 5.3 | 3.2% | Dec 1, 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo... |
| CVE-2020-28576 | MEDIUM | 5.3 | 3.2% | Dec 1, 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo... |
| CVE-2020-28575 | MEDIUM | 6.7 | 0.7% | Dec 1, 2020 | A heap-based buffer overflow privilege escalation vulnerability in Trend Micro ServerProtect for Linux 3.0 may allow an ... |
| CVE-2020-28573 | MEDIUM | 5.3 | 3.2% | Dec 1, 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allo... |
| CVE-2020-29315 | MEDIUM | 5.4 | 1.0% | Dec 1, 2020 | ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script ... |
| CVE-2020-7546 | MEDIUM | 5.4 | 0.6% | Dec 1, 2020 | A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStru... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now