2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0592 | MEDIUM | 6.7 | 0.3% | Nov 12, 2020 | Out of bounds write in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable ... |
| CVE-2020-0591 | MEDIUM | 6.7 | 0.3% | Nov 12, 2020 | Improper buffer restrictions in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially en... |
| CVE-2020-0588 | MEDIUM | 6.7 | 0.3% | Nov 12, 2020 | Improper conditions check in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enabl... |
| CVE-2020-0587 | MEDIUM | 6.7 | 0.3% | Nov 12, 2020 | Improper conditions check in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enabl... |
| CVE-2020-0584 | MEDIUM | 6.2 | 0.3% | Nov 12, 2020 | Buffer overflow in firmware for Intel(R) SSD DC P4800X and P4801X Series, Intel(R) Optane(TM) SSD 900P and 905P Series m... |
| CVE-2020-0575 | MEDIUM | 5.5 | 0.3% | Nov 12, 2020 | Improper buffer restrictions in the Intel(R) Unite Client for Windows* before version 4.2.13064 may allow an authenticat... |
| CVE-2020-24443 | MEDIUM | 6.1 | 1.5% | Nov 12, 2020 | Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an atta... |
| CVE-2020-24442 | MEDIUM | 6.1 | 1.5% | Nov 12, 2020 | Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an atta... |
| CVE-2020-24441 | MEDIUM | 5.5 | 2.3% | Nov 12, 2020 | Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created b... |
| CVE-2020-9128 | MEDIUM | 4.4 | 0.1% | Nov 12, 2020 | FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can ex... |
| CVE-2020-25706 | MEDIUM | 6.1 | 2.8% | Nov 12, 2020 | A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of err... |
| CVE-2020-25658 | MEDIUM | 5.9 | 1.6% | Nov 12, 2020 | It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA d... |
| CVE-2020-13954 | MEDIUM | 6.1 | 43.0% | Nov 12, 2020 | By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This... |
| CVE-2020-7333 | MEDIUM | 4.8 | 0.5% | Nov 12, 2020 | Cross site scripting vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 Novem... |
| CVE-2020-11209 | MEDIUM | 5.5 | 1.6% | Nov 12, 2020 | Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, ... |
| CVE-2020-11123 | MEDIUM | 5.5 | 0.2% | Nov 12, 2020 | u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attem... |
| CVE-2020-1999 | MEDIUM | 5.3 | 1.3% | Nov 12, 2020 | A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker t... |
| CVE-2020-26221 | MEDIUM | 6.1 | 0.6% | Nov 11, 2020 | touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to sen... |
| CVE-2020-26219 | MEDIUM | 6.1 | 0.6% | Nov 11, 2020 | touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information ... |
| CVE-2020-26218 | MEDIUM | 6.1 | 1.9% | Nov 11, 2020 | touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting. The vulnerability allows an attacker to inject HT... |
| CVE-2020-8354 | MEDIUM | 6.7 | 0.2% | Nov 11, 2020 | A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook mod... |
| CVE-2020-8353 | MEDIUM | 6.7 | 0.5% | Nov 11, 2020 | Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configur... |
| CVE-2020-15275 | MEDIUM | 5.4 | 1.7% | Nov 11, 2020 | MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file ... |
| CVE-2020-7767 | MEDIUM | 5.3 | 1.6% | Nov 11, 2020 | All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validatin... |
| CVE-2020-1599 | MEDIUM | 5.5 | 19.1% | Nov 11, 2020 | Windows Spoofing Vulnerability |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now