2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26511 | HIGH | 7.5 | 2.1% | Oct 2, 2020 | The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This lead... |
| CVE-2020-9491 | HIGH | 7.5 | 2.8% | Oct 1, 2020 | In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connectio... |
| CVE-2020-9487 | HIGH | 7.5 | 3.0% | Oct 1, 2020 | In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did no... |
| CVE-2020-9486 | HIGH | 7.5 | 3.4% | Oct 1, 2020 | In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive proper... |
| CVE-2020-5786 | HIGH | 8.8 | 8.8% | Oct 1, 2020 | Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive applica... |
| CVE-2020-11979 | HIGH | 7.5 | 8.1% | Oct 1, 2020 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the... |
| CVE-2020-15678 | HIGH | 8.8 | 1.9% | Oct 1, 2020 | When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential u... |
| CVE-2020-15675 | HIGH | 8.8 | 1.0% | Oct 1, 2020 | When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially ex... |
| CVE-2020-15674 | HIGH | 8.8 | 0.8% | Oct 1, 2020 | Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corru... |
| CVE-2020-15673 | HIGH | 8.8 | 1.9% | Oct 1, 2020 | Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evi... |
| CVE-2020-15670 | HIGH | 8.8 | 1.1% | Oct 1, 2020 | Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of ... |
| CVE-2020-15669 | HIGH | 8.8 | 1.1% | Oct 1, 2020 | When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. T... |
| CVE-2020-15667 | HIGH | 8.8 | 1.6% | Oct 1, 2020 | When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap... |
| CVE-2020-15663 | HIGH | 8.8 | 2.6% | Oct 1, 2020 | If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the... |
| CVE-2020-25018 | HIGH | 7.5 | 1.1% | Oct 1, 2020 | Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization. |
| CVE-2020-25017 | HIGH | 8.3 | 1.3% | Oct 1, 2020 | Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy... |
| CVE-2020-24620 | HIGH | 7.8 | 0.3% | Oct 1, 2020 | Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager ... |
| CVE-2020-4576 | HIGH | 7.5 | 2.0% | Oct 1, 2020 | IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive in... |
| CVE-2020-8109 | HIGH | 7.5 | 0.9% | Oct 1, 2020 | A vulnerability has been discovered in the ace.xmd parser that results from a lack of proper validation of user-supplied... |
| CVE-2020-6654 | HIGH | 7.8 | 0.4% | Sep 30, 2020 | A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attac... |
| CVE-2020-16234 | HIGH | 7.8 | 1.3% | Sep 30, 2020 | In PLC WinProladder Version 3.28 and prior, a stack-based buffer overflow vulnerability can be exploited when a valid us... |
| CVE-2020-13952 | HIGH | 8.1 | 2.0% | Sep 30, 2020 | In the course of work on the open source project it was discovered that authenticated users running queries against Hive... |
| CVE-2020-12715 | HIGH | 8.8 | 1.2% | Sep 30, 2020 | RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control. |
| CVE-2020-14374 | HIGH | 8.8 | 0.4% | Sep 30, 2020 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data funct... |
| CVE-2020-15849 | HIGH | 7.2 | 2.7% | Sep 30, 2020 | Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTem... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now