2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3403 | HIGH | 7.8 | 0.4% | Sep 24, 2020 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to ... |
| CVE-2020-3400 | HIGH | 8.8 | 1.0% | Sep 24, 2020 | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize ... |
| CVE-2020-3399 | HIGH | 8.6 | 1.4% | Sep 24, 2020 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE S... |
| CVE-2020-3396 | HIGH | 7.2 | 0.3% | Sep 24, 2020 | A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allo... |
| CVE-2020-3393 | HIGH | 7.8 | 0.3% | Sep 24, 2020 | A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attack... |
| CVE-2020-3390 | HIGH | 7.4 | 0.6% | Sep 24, 2020 | A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wi... |
| CVE-2020-3359 | HIGH | 8.6 | 1.5% | Sep 24, 2020 | A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Con... |
| CVE-2020-3141 | HIGH | 8.8 | 1.8% | Sep 24, 2020 | Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote a... |
| CVE-2020-15223 | HIGH | 8 | 1.6% | Sep 24, 2020 | In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationH... |
| CVE-2020-15222 | HIGH | 8.1 | 0.9% | Sep 24, 2020 | In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_k... |
| CVE-2020-13119 | HIGH | 8.1 | 0.8% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to clickjacking. |
| CVE-2020-12837 | HIGH | 7.5 | 0.9% | Sep 24, 2020 | ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magi... |
| CVE-2020-12282 | HIGH | 8.8 | 0.5% | Sep 24, 2020 | iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible ... |
| CVE-2020-24365 | HIGH | 8.8 | 11.4% | Sep 24, 2020 | An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic n... |
| CVE-2020-12817 | HIGH | 8.8 | 2.3% | Sep 24, 2020 | An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticat... |
| CVE-2020-16148 | HIGH | 7.2 | 1.9% | Sep 24, 2020 | The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell... |
| CVE-2020-24560 | HIGH | 7.5 | 1.8% | Sep 24, 2020 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o... |
| CVE-2020-15604 | HIGH | 7.5 | 1.6% | Sep 24, 2020 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o... |
| CVE-2020-25603 | HIGH | 7.8 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event chan... |
| CVE-2020-25599 | HIGH | 7 | 0.3% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potenti... |
| CVE-2020-25595 | HIGH | 7.8 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen... |
| CVE-2020-11031 | HIGH | 7.5 | 0.3% | Sep 23, 2020 | In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on th... |
| CVE-2020-24213 | HIGH | 7.5 | 1.1% | Sep 23, 2020 | An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memor... |
| CVE-2020-2284 | HIGH | 7.1 | 0.9% | Sep 23, 2020 | Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE)... |
| CVE-2020-2280 | HIGH | 8.8 | 1.1% | Sep 23, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execu... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now