2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15839 | MEDIUM | 6.5 | 2.2% | Sep 22, 2020 | Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the siz... |
| CVE-2020-14027 | MEDIUM | 5.3 | 0.8% | Sep 22, 2020 | An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arg... |
| CVE-2020-14024 | MEDIUM | 6.1 | 0.7% | Sep 22, 2020 | Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) R... |
| CVE-2020-14023 | MEDIUM | 4.9 | 1.0% | Sep 22, 2020 | Ozeki NG SMS Gateway through 4.17.6 allows SSRF via SMS WCF or RSS To SMS. |
| CVE-2020-24333 | MEDIUM | 6.5 | 0.8% | Sep 22, 2020 | A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rig... |
| CVE-2020-4619 | MEDIUM | 6.5 | 0.7% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated ... |
| CVE-2020-4618 | MEDIUM | 4.9 | 1.1% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow a privileged user to cause a denial of service due to improper input vali... |
| CVE-2020-4616 | MEDIUM | 5.3 | 1.7% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could disclose sensitive username information to an attacker using a specially crafte... |
| CVE-2020-4615 | MEDIUM | 5.4 | 0.7% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2020-4612 | MEDIUM | 6.5 | 1.3% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to obtain sensitive information using a specially c... |
| CVE-2020-3977 | MEDIUM | 6.5 | 1.0% | Sep 22, 2020 | VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in ... |
| CVE-2020-23446 | MEDIUM | 5.3 | 1.5% | Sep 22, 2020 | Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API |
| CVE-2020-24619 | MEDIUM | 5.9 | 0.7% | Sep 22, 2020 | In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::Ver... |
| CVE-2020-6571 | MEDIUM | 4.3 | 1.3% | Sep 21, 2020 | Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform doma... |
| CVE-2020-6570 | MEDIUM | 4.3 | 1.2% | Sep 21, 2020 | Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sen... |
| CVE-2020-6569 | MEDIUM | 6.3 | 1.3% | Sep 21, 2020 | Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the rend... |
| CVE-2020-6568 | MEDIUM | 6.5 | 1.5% | Sep 21, 2020 | Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote at... |
| CVE-2020-6567 | MEDIUM | 6.5 | 1.5% | Sep 21, 2020 | Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 al... |
| CVE-2020-6566 | MEDIUM | 6.5 | 1.6% | Sep 21, 2020 | Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-... |
| CVE-2020-6565 | MEDIUM | 6.5 | 1.5% | Sep 21, 2020 | Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof... |
| CVE-2020-6564 | MEDIUM | 6.5 | 1.5% | Sep 21, 2020 | Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof th... |
| CVE-2020-6563 | MEDIUM | 6.5 | 1.7% | Sep 21, 2020 | Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote at... |
| CVE-2020-6562 | MEDIUM | 6.5 | 1.5% | Sep 21, 2020 | Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-... |
| CVE-2020-6561 | MEDIUM | 6.5 | 1.5% | Sep 21, 2020 | Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker... |
| CVE-2020-6560 | MEDIUM | 6.5 | 1.6% | Sep 21, 2020 | Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cro... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now