2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3996 | MEDIUM | 5.5 | 0.3% | Oct 22, 2020 | Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in infor... |
| CVE-2020-27675 | MEDIUM | 4.7 | 0.3% | Oct 22, 2020 | An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_ba... |
| CVE-2020-27674 | MEDIUM | 5.3 | 0.4% | Oct 22, 2020 | An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying ke... |
| CVE-2020-27673 | MEDIUM | 5.5 | 0.4% | Oct 22, 2020 | An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a d... |
| CVE-2020-15682 | MEDIUM | 6.5 | 0.5% | Oct 22, 2020 | When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application... |
| CVE-2020-15680 | MEDIUM | 5.3 | 0.9% | Oct 22, 2020 | If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguis... |
| CVE-2020-9997 | MEDIUM | 5.5 | 0.8% | Oct 22, 2020 | An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.1... |
| CVE-2020-9939 | MEDIUM | 6.4 | 0.2% | Oct 22, 2020 | This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A local user may be able t... |
| CVE-2020-9935 | MEDIUM | 4.3 | 0.7% | Oct 22, 2020 | A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6. A user may be... |
| CVE-2020-9902 | MEDIUM | 5.5 | 1.0% | Oct 22, 2020 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macO... |
| CVE-2020-27666 | MEDIUM | 5.4 | 0.6% | Oct 22, 2020 | Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature. |
| CVE-2020-9810 | MEDIUM | 6.8 | 0.3% | Oct 22, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A person with phy... |
| CVE-2020-9787 | MEDIUM | 5.3 | 1.3% | Oct 22, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina ... |
| CVE-2020-9772 | MEDIUM | 5.5 | 0.3% | Oct 22, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina ... |
| CVE-2020-3918 | MEDIUM | 5.5 | 0.3% | Oct 22, 2020 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, mac... |
| CVE-2020-27533 | MEDIUM | 5.4 | 3.5% | Oct 22, 2020 | A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to ... |
| CVE-2020-26650 | MEDIUM | 5.3 | 1.0% | Oct 22, 2020 | AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php |
| CVE-2020-27646 | MEDIUM | 6.5 | 1.0% | Oct 22, 2020 | Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft. |
| CVE-2020-27642 | MEDIUM | 6.1 | 0.7% | Oct 22, 2020 | A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Gre... |
| CVE-2020-27621 | MEDIUM | 4.3 | 0.7% | Oct 22, 2020 | The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific u... |
| CVE-2020-27620 | MEDIUM | 6.1 | 0.9% | Oct 22, 2020 | The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. ... |
| CVE-2020-24421 | MEDIUM | 5.5 | 1.8% | Oct 21, 2020 | Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a ma... |
| CVE-2020-17454 | MEDIUM | 6.1 | 0.8% | Oct 21, 2020 | WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it ... |
| CVE-2020-27344 | MEDIUM | 6.1 | 1.0% | Oct 21, 2020 | The cm-download-manager plugin before 2.8.0 for WordPress allows XSS. |
| CVE-2020-3599 | MEDIUM | 6.1 | 0.8% | Oct 21, 2020 | A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now