2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14382 | HIGH | 7.8 | 1.2% | Sep 16, 2020 | A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, tha... |
| CVE-2020-10733 | HIGH | 7.3 | 0.5% | Sep 16, 2020 | The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths... |
| CVE-2020-7733 | HIGH | 7.5 | 4.5% | Sep 16, 2020 | The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for ... |
| CVE-2020-2276 | HIGH | 8.8 | 1.6% | Sep 16, 2020 | Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing att... |
| CVE-2020-2268 | HIGH | 8.8 | 0.7% | Sep 16, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain acc... |
| CVE-2020-2261 | HIGH | 8.8 | 1.4% | Sep 16, 2020 | Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Confi... |
| CVE-2020-14393 | HIGH | 7.1 | 0.6% | Sep 16, 2020 | A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 3... |
| CVE-2020-25559 | HIGH | 7.8 | 1.6% | Sep 16, 2020 | gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary c... |
| CVE-2020-14386 | HIGH | 7.8 | 1.3% | Sep 16, 2020 | A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unp... |
| CVE-2020-25453 | HIGH | 8.8 | 6.3% | Sep 15, 2020 | An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote... |
| CVE-2020-11977 | HIGH | 7.2 | 2.8% | Sep 15, 2020 | In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow ... |
| CVE-2020-15172 | HIGH | 8.8 | 1.8% | Sep 15, 2020 | The Act module for Red Discord Bot before commit 6b9f3b86 is vulnerable to Remote Code Execution. With this exploit, Dis... |
| CVE-2020-14362 | HIGH | 7.8 | 0.6% | Sep 15, 2020 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may... |
| CVE-2020-14361 | HIGH | 7.8 | 0.6% | Sep 15, 2020 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may... |
| CVE-2020-14346 | HIGH | 7.8 | 0.6% | Sep 15, 2020 | A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in th... |
| CVE-2020-8342 | HIGH | 7 | 0.2% | Sep 15, 2020 | A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalati... |
| CVE-2020-4703 | HIGH | 8 | 1.8% | Sep 15, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload a... |
| CVE-2020-4521 | HIGH | 8.8 | 6.5% | Sep 15, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the... |
| CVE-2020-23451 | HIGH | 8.8 | 0.6% | Sep 15, 2020 | Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" func... |
| CVE-2020-16101 | HIGH | 7.5 | 1.0% | Sep 15, 2020 | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out... |
| CVE-2020-16100 | HIGH | 7.5 | 1.0% | Sep 15, 2020 | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websoc... |
| CVE-2020-16096 | HIGH | 7.7 | 0.8% | Sep 15, 2020 | In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(... |
| CVE-2020-14345 | HIGH | 7.8 | 0.6% | Sep 15, 2020 | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead... |
| CVE-2020-24925 | HIGH | 7.5 | 1.0% | Sep 15, 2020 | A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the pa... |
| CVE-2020-15590 | HIGH | 7.5 | 2.5% | Sep 14, 2020 | A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to by... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now