2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11125 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Out of bound access can happen in MHI command process due to lack of check of channel id value received from MHI devic... |
| CVE-2020-11114 | HIGH | 8.8 | 0.4% | Nov 2, 2020 | u'Bluetooth devices does not properly restrict the L2CAP payload length allowing users in radio range to cause a buffer ... |
| CVE-2020-25849 | HIGH | 8.8 | 2.2% | Nov 1, 2020 | MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands... |
| CVE-2020-5425 | HIGH | 7.9 | 0.7% | Oct 31, 2020 | Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1... |
| CVE-2020-5991 | HIGH | 7.8 | 0.5% | Oct 30, 2020 | NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bou... |
| CVE-2020-15276 | HIGH | 8.7 | 1.0% | Oct 30, 2020 | baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a ... |
| CVE-2020-15273 | HIGH | 8.1 | 1.0% | Oct 30, 2020 | baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit fe... |
| CVE-2020-15277 | HIGH | 7.2 | 2.2% | Oct 30, 2020 | baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system... |
| CVE-2020-4588 | HIGH | 7.8 | 1.3% | Oct 30, 2020 | IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting... |
| CVE-2020-4584 | HIGH | 7.5 | 1.0% | Oct 30, 2020 | IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error messag... |
| CVE-2020-7760 | HIGH | 7.5 | 5.2% | Oct 30, 2020 | This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The... |
| CVE-2020-7759 | HIGH | 7.2 | 1.3% | Oct 30, 2020 | The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functiona... |
| CVE-2020-25646 | HIGH | 7.5 | 1.4% | Oct 29, 2020 | A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This direc... |
| CVE-2020-27887 | HIGH | 8.8 | 1.7% | Oct 29, 2020 | An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could a... |
| CVE-2020-27996 | HIGH | 8.8 | 2.1% | Oct 29, 2020 | An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttri... |
| CVE-2020-25780 | HIGH | 7.5 | 9.9% | Oct 29, 2020 | In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, D... |
| CVE-2020-5936 | HIGH | 7.5 | 1.1% | Oct 29, 2020 | On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel... |
| CVE-2020-5933 | HIGH | 7.5 | 1.1% | Oct 29, 2020 | On versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, when a BIG-IP syste... |
| CVE-2020-5931 | HIGH | 7.5 | 1.0% | Oct 29, 2020 | On BIG-IP 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, Virtual servers with ... |
| CVE-2020-4724 | HIGH | 7.8 | 1.5% | Oct 29, 2020 | IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by ... |
| CVE-2020-4723 | HIGH | 7.8 | 1.5% | Oct 29, 2020 | IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by ... |
| CVE-2020-4722 | HIGH | 7.8 | 1.5% | Oct 29, 2020 | IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by ... |
| CVE-2020-4721 | HIGH | 7.8 | 1.5% | Oct 29, 2020 | IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by ... |
| CVE-2020-7384 | HIGH | 7.8 | 30.6% | Oct 29, 2020 | Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish ... |
| CVE-2020-5937 | HIGH | 7.5 | 1.3% | Oct 29, 2020 | On BIG-IP AFM 15.1.0-15.1.0.5, the Traffic Management Microkernel (TMM) may produce a core file while processing layer 4... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now