2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13943 | MEDIUM | 4.3 | 57.3% | Oct 12, 2020 | If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded t... |
| CVE-2020-13341 | MEDIUM | 4.9 | 1.2% | Oct 12, 2020 | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permissi... |
| CVE-2020-4781 | MEDIUM | 6.5 | 1.4% | Oct 12, 2020 | An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 ... |
| CVE-2020-4780 | MEDIUM | 5.3 | 1.0% | Oct 12, 2020 | OOTB build scripts does not set the secure attribute on session cookie which may impact IBM Curam Social Program Managem... |
| CVE-2020-4775 | MEDIUM | 5.4 | 0.6% | Oct 12, 2020 | A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnera... |
| CVE-2020-4774 | MEDIUM | 5.4 | 0.8% | Oct 12, 2020 | An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling ... |
| CVE-2020-4773 | MEDIUM | 6.5 | 0.6% | Oct 12, 2020 | A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which... |
| CVE-2020-4699 | MEDIUM | 5.3 | 0.4% | Oct 12, 2020 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin... |
| CVE-2020-4661 | MEDIUM | 5.3 | 0.4% | Oct 12, 2020 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin... |
| CVE-2020-4660 | MEDIUM | 5.3 | 0.4% | Oct 12, 2020 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin... |
| CVE-2020-5143 | MEDIUM | 5.3 | 1.6% | Oct 12, 2020 | SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username... |
| CVE-2020-5142 | MEDIUM | 6.1 | 1.1% | Oct 12, 2020 | A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated a... |
| CVE-2020-5141 | MEDIUM | 6.5 | 1.3% | Oct 12, 2020 | A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firew... |
| CVE-2020-5136 | MEDIUM | 6.5 | 1.1% | Oct 12, 2020 | A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-... |
| CVE-2020-5134 | MEDIUM | 6.5 | 1.1% | Oct 12, 2020 | A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a fire... |
| CVE-2020-14184 | MEDIUM | 5.4 | 0.9% | Oct 12, 2020 | Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Sit... |
| CVE-2020-26934 | MEDIUM | 6.1 | 2.2% | Oct 10, 2020 | phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link. |
| CVE-2020-26932 | MEDIUM | 4.3 | 1.0% | Oct 10, 2020 | debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whe... |
| CVE-2020-9105 | MEDIUM | 6.7 | 0.2% | Oct 9, 2020 | Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to t... |
| CVE-2020-13955 | MEDIUM | 5.9 | 2.1% | Oct 9, 2020 | HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnera... |
| CVE-2020-26931 | MEDIUM | 6.5 | 0.4% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WC7500 before 6.5.5.24, WC7600... |
| CVE-2020-26924 | MEDIUM | 6.5 | 0.6% | Oct 9, 2020 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WAC720 before 3.9.1.13 and WAC... |
| CVE-2020-26923 | MEDIUM | 4.8 | 0.5% | Oct 9, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v... |
| CVE-2020-26922 | MEDIUM | 6.7 | 0.4% | Oct 9, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24,... |
| CVE-2020-26918 | MEDIUM | 4.8 | 0.6% | Oct 9, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 be... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now