2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15928 | MEDIUM | 5.3 | 1.7% | Nov 24, 2020 | In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory trav... |
| CVE-2020-26231 | MEDIUM | 6.7 | 0.3% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 ... |
| CVE-2020-26227 | MEDIUM | 6.1 | 0.7% | Nov 23, 2020 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system ... |
| CVE-2020-15437 | MEDIUM | 4.4 | 0.4% | Nov 23, 2020 | The Linux kernel before version 5.8 is vulnerable to a NULL pointer dereference in drivers/tty/serial/8250/8250_core.c:s... |
| CVE-2020-15436 | MEDIUM | 6.7 | 0.9% | Nov 23, 2020 | Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or c... |
| CVE-2020-28927 | MEDIUM | 6.1 | 0.7% | Nov 23, 2020 | There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user secti... |
| CVE-2020-15249 | MEDIUM | 5.4 | 0.5% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version... |
| CVE-2020-15248 | MEDIUM | 4.2 | 0.3% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version... |
| CVE-2020-15247 | MEDIUM | 5.2 | 0.3% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version... |
| CVE-2020-7927 | MEDIUM | 6.5 | 1.0% | Nov 23, 2020 | Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key ... |
| CVE-2020-28896 | MEDIUM | 5.3 | 2.3% | Nov 23, 2020 | Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's ini... |
| CVE-2020-26239 | MEDIUM | 5.4 | 1.0% | Nov 23, 2020 | Scratch Addons is a WebExtension that supports both Chrome and Firefox. Scratch Addons before version 1.3.2 is vulnerabl... |
| CVE-2020-7928 | MEDIUM | 6.5 | 1.4% | Nov 23, 2020 | A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing speciall... |
| CVE-2020-4783 | MEDIUM | 5.9 | 1.2% | Nov 23, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by... |
| CVE-2020-4771 | MEDIUM | 5.3 | 1.5% | Nov 23, 2020 | IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attack... |
| CVE-2020-12352 | MEDIUM | 6.5 | 5.7% | Nov 23, 2020 | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja... |
| CVE-2020-0569 | MEDIUM | 5.7 | 0.6% | Nov 23, 2020 | Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potential... |
| CVE-2020-1778 | MEDIUM | 4.3 | 0.6% | Nov 23, 2020 | When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is se... |
| CVE-2020-7926 | MEDIUM | 6.5 | 1.4% | Nov 23, 2020 | A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which vio... |
| CVE-2020-28053 | MEDIUM | 6.5 | 1.4% | Nov 23, 2020 | HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read th... |
| CVE-2020-5797 | MEDIUM | 6.1 | 0.6% | Nov 21, 2020 | UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with... |
| CVE-2020-25725 | MEDIUM | 5.5 | 1.0% | Nov 21, 2020 | In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3Glyph... |
| CVE-2020-20739 | MEDIUM | 5.3 | 2.0% | Nov 20, 2020 | im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may c... |
| CVE-2020-28974 | MEDIUM | 5 | 0.5% | Nov 20, 2020 | A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged ... |
| CVE-2020-7842 | MEDIUM | 6.6 | 1.5% | Nov 20, 2020 | Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection an... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now