2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8332 | MEDIUM | 6.4 | 0.2% | Oct 14, 2020 | A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo an... |
| CVE-2020-7318 | MEDIUM | 4.3 | 1.0% | Oct 14, 2020 | Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators t... |
| CVE-2020-7317 | MEDIUM | 4.3 | 0.3% | Oct 14, 2020 | Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators t... |
| CVE-2020-3483 | MEDIUM | 6.3 | 0.1% | Oct 14, 2020 | Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL cer... |
| CVE-2020-15253 | MEDIUM | 4.8 | 1.2% | Oct 14, 2020 | Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered ... |
| CVE-2020-15224 | MEDIUM | 6.8 | 0.6% | Oct 14, 2020 | In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using ... |
| CVE-2020-4395 | MEDIUM | 5.4 | 0.6% | Oct 14, 2020 | IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated ... |
| CVE-2020-27013 | MEDIUM | 4.4 | 0.4% | Oct 14, 2020 | Trend Micro Antivirus for Mac 2020 (Consumer) contains a vulnerability in the product that occurs when a webserver is st... |
| CVE-2020-25778 | MEDIUM | 6 | 0.6% | Oct 14, 2020 | Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in a specific kernel extension where an attacker could... |
| CVE-2020-25777 | MEDIUM | 5.4 | 1.3% | Oct 14, 2020 | Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a specific kernel extension request attack where an attac... |
| CVE-2020-24188 | MEDIUM | 6.1 | 0.8% | Oct 14, 2020 | Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to ... |
| CVE-2020-6933 | MEDIUM | 5.5 | 0.3% | Oct 14, 2020 | An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earli... |
| CVE-2020-0419 | MEDIUM | 5.5 | 0.1% | Oct 14, 2020 | In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installat... |
| CVE-2020-0415 | MEDIUM | 5.5 | 0.2% | Oct 14, 2020 | In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead ... |
| CVE-2020-0414 | MEDIUM | 6.5 | 1.0% | Oct 14, 2020 | In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silenced audio buffer due... |
| CVE-2020-0411 | MEDIUM | 6.5 | 0.8% | Oct 14, 2020 | In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could le... |
| CVE-2020-0410 | MEDIUM | 5.5 | 0.1% | Oct 14, 2020 | In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lea... |
| CVE-2020-0400 | MEDIUM | 5.5 | 0.2% | Oct 14, 2020 | In showDataRoamingNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIn... |
| CVE-2020-0398 | MEDIUM | 5.5 | 0.2% | Oct 14, 2020 | In updateMwi of NotificationMgr.java, there is a possible permission bypass due to a PendingIntent error. This could lea... |
| CVE-2020-0378 | MEDIUM | 5.5 | 0.2% | Oct 14, 2020 | In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local informatio... |
| CVE-2020-0246 | MEDIUM | 5.5 | 0.2% | Oct 14, 2020 | In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local infor... |
| CVE-2020-24551 | MEDIUM | 6.1 | 0.6% | Oct 14, 2020 | IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to red... |
| CVE-2020-12933 | MEDIUM | 5.5 | 0.3% | Oct 13, 2020 | A denial of service vulnerability exists in the D3DKMTEscape handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.... |
| CVE-2020-12911 | MEDIUM | 5.5 | 0.3% | Oct 13, 2020 | A denial of service vulnerability exists in the D3DKMTCreateAllocation handler functionality of AMD ATIKMDAG.SYS (e.g. v... |
| CVE-2020-15251 | MEDIUM | 6.5 | 1.1% | Oct 13, 2020 | In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now