2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8276 | MEDIUM | 5.5 | 0.4% | Nov 9, 2020 | The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the times... |
| CVE-2020-8150 | MEDIUM | 4.1 | 0.3% | Nov 9, 2020 | A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the in... |
| CVE-2020-8133 | MEDIUM | 5.3 | 0.7% | Nov 9, 2020 | A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite... |
| CVE-2020-25655 | MEDIUM | 6.5 | 0.6% | Nov 9, 2020 | An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct... |
| CVE-2020-24353 | MEDIUM | 6.1 | 0.6% | Nov 9, 2020 | Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header. |
| CVE-2020-28351 | MEDIUM | 6.1 | 16.0% | Nov 9, 2020 | The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r... |
| CVE-2020-28349 | MEDIUM | 6.5 | 2.2% | Nov 9, 2020 | An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplin... |
| CVE-2020-24405 | MEDIUM | 4.3 | 1.5% | Nov 9, 2020 | Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions issue vulnerability in the Inve... |
| CVE-2020-24402 | MEDIUM | 4.9 | 1.7% | Nov 9, 2020 | Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability in the Integratio... |
| CVE-2020-24401 | MEDIUM | 6.5 | 2.3% | Nov 9, 2020 | Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can st... |
| CVE-2020-28168 | MEDIUM | 5.9 | 2.3% | Nov 6, 2020 | Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass... |
| CVE-2020-3592 | MEDIUM | 6.5 | 0.8% | Nov 6, 2020 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem... |
| CVE-2020-3591 | MEDIUM | 4.3 | 0.7% | Nov 6, 2020 | A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated,... |
| CVE-2020-3590 | MEDIUM | 6.4 | 0.6% | Nov 6, 2020 | A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated,... |
| CVE-2020-3587 | MEDIUM | 6.4 | 0.6% | Nov 6, 2020 | A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated,... |
| CVE-2020-3579 | MEDIUM | 6.1 | 0.8% | Nov 6, 2020 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, r... |
| CVE-2020-3551 | MEDIUM | 6.1 | 0.8% | Nov 6, 2020 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2020-28327 | MEDIUM | 5.3 | 2.0% | Nov 6, 2020 | A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 1... |
| CVE-2020-27129 | MEDIUM | 6.7 | 0.3% | Nov 6, 2020 | A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local at... |
| CVE-2020-27128 | MEDIUM | 6.5 | 60.8% | Nov 6, 2020 | A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote ... |
| CVE-2020-27123 | MEDIUM | 5.5 | 0.3% | Nov 6, 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c... |
| CVE-2020-27122 | MEDIUM | 6.7 | 0.3% | Nov 6, 2020 | A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an aut... |
| CVE-2020-27121 | MEDIUM | 6.5 | 1.1% | Nov 6, 2020 | A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could a... |
| CVE-2020-26086 | MEDIUM | 4.3 | 0.8% | Nov 6, 2020 | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow ... |
| CVE-2020-26084 | MEDIUM | 6.5 | 0.9% | Nov 6, 2020 | A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files o... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now