2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4128 | MEDIUM | 5.3 | 0.9% | Dec 1, 2020 | HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker ... |
| CVE-2020-15257 | MEDIUM | 5.2 | 3.2% | Dec 1, 2020 | containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd b... |
| CVE-2020-4129 | MEDIUM | 5.3 | 0.9% | Dec 1, 2020 | HCL Domino is susceptible to a lockout policy bypass vulnerability in the LDAP service. An unauthenticated attacker coul... |
| CVE-2020-4126 | MEDIUM | 5.9 | 0.7% | Dec 1, 2020 | HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacke... |
| CVE-2020-14193 | MEDIUM | 5.4 | 0.8% | Nov 30, 2020 | Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache template... |
| CVE-2020-4127 | MEDIUM | 6.5 | 0.5% | Nov 30, 2020 | HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into ac... |
| CVE-2020-29441 | MEDIUM | 6.5 | 0.9% | Nov 30, 2020 | An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker c... |
| CVE-2020-29440 | MEDIUM | 4.6 | 0.2% | Nov 30, 2020 | Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob w... |
| CVE-2020-29439 | MEDIUM | 4.6 | 0.4% | Nov 30, 2020 | Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a ... |
| CVE-2020-29438 | MEDIUM | 6.5 | 0.4% | Nov 30, 2020 | Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This... |
| CVE-2020-29395 | MEDIUM | 6.1 | 11.7% | Nov 30, 2020 | The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field. |
| CVE-2020-27587 | MEDIUM | 6.7 | 0.4% | Nov 30, 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vau... |
| CVE-2020-27586 | MEDIUM | 5.9 | 0.7% | Nov 30, 2020 | Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text. |
| CVE-2020-27585 | MEDIUM | 4.4 | 0.3% | Nov 30, 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings v... |
| CVE-2020-17901 | MEDIUM | 6.5 | 0.4% | Nov 30, 2020 | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. |
| CVE-2020-29392 | MEDIUM | 4.6 | 0.4% | Nov 30, 2020 | The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical acce... |
| CVE-2020-29364 | MEDIUM | 4.8 | 0.6% | Nov 30, 2020 | In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news tit... |
| CVE-2020-4900 | MEDIUM | 5.5 | 0.3% | Nov 30, 2020 | IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a ... |
| CVE-2020-4696 | MEDIUM | 4.3 | 0.7% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated use... |
| CVE-2020-4626 | MEDIUM | 4.3 | 1.0% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1 (CP4S) could reveal sensitive information about the internal network to an authentica... |
| CVE-2020-4625 | MEDIUM | 5.3 | 1.5% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the fa... |
| CVE-2020-4624 | MEDIUM | 5.3 | 0.7% | Nov 30, 2020 | IBM Cloud Pak for Security 1.3.0.1 (CP4S) uses weaker than expected cryptographic algorithms during negotiation could al... |
| CVE-2020-29384 | MEDIUM | 5.5 | 1.0% | Nov 30, 2020 | An issue was discovered in PNGOUT 2020-01-15. When compressing a crafted PNG file, it encounters an integer overflow. |
| CVE-2020-28978 | MEDIUM | 5.3 | 15.3% | Nov 30, 2020 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a... |
| CVE-2020-28977 | MEDIUM | 5.3 | 15.3% | Nov 30, 2020 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now