2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8580 | HIGH | 7.5 | 1.3% | Nov 6, 2020 | SANtricity OS Controller Software versions 11.30 and higher are susceptible to a vulnerability which allows an unauthent... |
| CVE-2020-7198 | HIGH | 8.8 | 2.0% | Nov 6, 2020 | There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synerg... |
| CVE-2020-27589 | HIGH | 7.5 | 1.1% | Nov 6, 2020 | Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certa... |
| CVE-2020-27196 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly par... |
| CVE-2020-26883 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of craf... |
| CVE-2020-26882 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON... |
| CVE-2020-10292 | HIGH | 8.2 | 1.5% | Nov 6, 2020 | Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove ... |
| CVE-2020-10291 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove ... |
| CVE-2020-28196 | HIGH | 7.5 | 4.4% | Nov 6, 2020 | MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerbero... |
| CVE-2020-26521 | HIGH | 7.5 | 2.1% | Nov 6, 2020 | The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code). |
| CVE-2020-5649 | HIGH | 7.5 | 4.1% | Nov 6, 2020 | Resource management error vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT... |
| CVE-2020-5646 | HIGH | 7.5 | 4.1% | Nov 6, 2020 | NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT... |
| CVE-2020-5645 | HIGH | 7.5 | 3.8% | Nov 6, 2020 | Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBD... |
| CVE-2020-27347 | HIGH | 7.8 | 0.7% | Nov 6, 2020 | In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-o... |
| CVE-2020-15708 | HIGH | 7.8 | 0.4% | Nov 6, 2020 | Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker c... |
| CVE-2020-6877 | HIGH | 8.8 | 1.0% | Nov 5, 2020 | A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the a... |
| CVE-2020-25837 | HIGH | 7.5 | 1.0% | Nov 5, 2020 | Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerabil... |
| CVE-2020-25661 | HIGH | 8.8 | 1.8% | Nov 5, 2020 | A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled ... |
| CVE-2020-13537 | HIGH | 7.8 | 0.5% | Nov 5, 2020 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8... |
| CVE-2020-13536 | HIGH | 7.8 | 0.5% | Nov 5, 2020 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8... |
| CVE-2020-5946 | HIGH | 7.5 | 1.0% | Nov 5, 2020 | In BIG-IP Advanced WAF and FPS versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, under some circumstances,... |
| CVE-2020-5945 | HIGH | 8.4 | 1.3% | Nov 5, 2020 | In BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.2.7, undisclosed TMUI page contains a stored cross ... |
| CVE-2020-5942 | HIGH | 7.5 | 1.0% | Nov 5, 2020 | In BIG-IP PEM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-1... |
| CVE-2020-5941 | HIGH | 7.5 | 1.0% | Nov 5, 2020 | On BIG-IP versions 16.0.0-16.0.0.1 and 15.1.0-15.1.0.5, using the RESOLV::lookup command within an iRule may cause the T... |
| CVE-2020-5939 | HIGH | 7.5 | 1.0% | Nov 5, 2020 | In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.3, 15.0.0-15.0.1.3, 14.1.0-14.1.2.6, and 13.1.0-13.1.3.4, BIG-IP Virtual Edit... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now