2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-25604MEDIUM4.7An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. Wh...
CVE-2020-25602MEDIUM6An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to...
CVE-2020-25601MEDIUM5.5An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In pa...
CVE-2020-25600MEDIUM5.5An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so ...
CVE-2020-25598MEDIUM5.5An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Rea...
CVE-2020-25597MEDIUM6.5An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may...
CVE-2020-25596MEDIUM5.5An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The S...
CVE-2020-5783MEDIUM5.4In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.
CVE-2020-5782MEDIUM6.5In IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the d...
CVE-2020-5781MEDIUM4.3In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/confi...
CVE-2020-4340MEDIUM4.3IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate vali...
CVE-2020-4324MEDIUM4.3IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improp...
CVE-2020-2285MEDIUM4.3A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permi...
CVE-2020-2283MEDIUM5.4Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site s...
CVE-2020-2282MEDIUM4.3Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attacker...
CVE-2020-2281MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers ...
CVE-2020-25739MEDIUM6.1An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to ...
CVE-2020-16240MEDIUM5.3GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user acc...
CVE-2020-14370MEDIUM5.3An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecat...
CVE-2020-10687MEDIUM4.8A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to C...
CVE-2020-3137MEDIUM6.1A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthentic...
CVE-2020-3130MEDIUM6.5A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker t...
CVE-2020-3124MEDIUM6.5A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an un...
CVE-2020-3117MEDIUM4.7A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security ...
CVE-2020-3116MEDIUM5.5A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now