2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25604 | MEDIUM | 4.7 | 0.3% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. Wh... |
| CVE-2020-25602 | MEDIUM | 6 | 0.3% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to... |
| CVE-2020-25601 | MEDIUM | 5.5 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In pa... |
| CVE-2020-25600 | MEDIUM | 5.5 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so ... |
| CVE-2020-25598 | MEDIUM | 5.5 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Rea... |
| CVE-2020-25597 | MEDIUM | 6.5 | 0.4% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may... |
| CVE-2020-25596 | MEDIUM | 5.5 | 0.5% | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The S... |
| CVE-2020-5783 | MEDIUM | 5.4 | 0.4% | Sep 23, 2020 | In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms. |
| CVE-2020-5782 | MEDIUM | 6.5 | 1.0% | Sep 23, 2020 | In IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the d... |
| CVE-2020-5781 | MEDIUM | 4.3 | 0.9% | Sep 23, 2020 | In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/confi... |
| CVE-2020-4340 | MEDIUM | 4.3 | 0.7% | Sep 23, 2020 | IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate vali... |
| CVE-2020-4324 | MEDIUM | 4.3 | 1.2% | Sep 23, 2020 | IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improp... |
| CVE-2020-2285 | MEDIUM | 4.3 | 0.7% | Sep 23, 2020 | A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permi... |
| CVE-2020-2283 | MEDIUM | 5.4 | 0.7% | Sep 23, 2020 | Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site s... |
| CVE-2020-2282 | MEDIUM | 4.3 | 0.7% | Sep 23, 2020 | Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attacker... |
| CVE-2020-2281 | MEDIUM | 5.4 | 0.7% | Sep 23, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers ... |
| CVE-2020-25739 | MEDIUM | 6.1 | 1.4% | Sep 23, 2020 | An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to ... |
| CVE-2020-16240 | MEDIUM | 5.3 | 0.9% | Sep 23, 2020 | GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user acc... |
| CVE-2020-14370 | MEDIUM | 5.3 | 1.4% | Sep 23, 2020 | An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecat... |
| CVE-2020-10687 | MEDIUM | 4.8 | 1.1% | Sep 23, 2020 | A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to C... |
| CVE-2020-3137 | MEDIUM | 6.1 | 0.8% | Sep 23, 2020 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthentic... |
| CVE-2020-3130 | MEDIUM | 6.5 | 1.8% | Sep 23, 2020 | A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker t... |
| CVE-2020-3124 | MEDIUM | 6.5 | 0.5% | Sep 23, 2020 | A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an un... |
| CVE-2020-3117 | MEDIUM | 4.7 | 0.9% | Sep 23, 2020 | A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security ... |
| CVE-2020-3116 | MEDIUM | 5.5 | 0.7% | Sep 23, 2020 | A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now