2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9298 | HIGH | 7.5 | 1.3% | Aug 28, 2020 | The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an att... |
| CVE-2020-4559 | HIGH | 7.5 | 1.3% | Aug 28, 2020 | IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user... |
| CVE-2020-10518 | HIGH | 8.8 | 3.7% | Aug 27, 2020 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a... |
| CVE-2020-8602 | HIGH | 7.2 | 4.2% | Aug 27, 2020 | A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protecti... |
| CVE-2020-15605 | HIGH | 8.1 | 2.8% | Aug 27, 2020 | If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2... |
| CVE-2020-15601 | HIGH | 8.1 | 2.8% | Aug 27, 2020 | If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x co... |
| CVE-2020-24717 | HIGH | 7.8 | 0.5% | Aug 27, 2020 | OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by ... |
| CVE-2020-24716 | HIGH | 7.8 | 0.5% | Aug 27, 2020 | OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories. |
| CVE-2020-24196 | HIGH | 7.2 | 2.7% | Aug 27, 2020 | An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote... |
| CVE-2020-3517 | HIGH | 8.6 | 1.4% | Aug 27, 2020 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an un... |
| CVE-2020-3454 | HIGH | 7.2 | 2.6% | Aug 27, 2020 | A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject... |
| CVE-2020-3415 | HIGH | 8.8 | 0.8% | Aug 27, 2020 | A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthenticated, adjacent att... |
| CVE-2020-3398 | HIGH | 8.6 | 1.8% | Aug 27, 2020 | A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could a... |
| CVE-2020-3397 | HIGH | 8.6 | 1.8% | Aug 27, 2020 | A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could a... |
| CVE-2020-3394 | HIGH | 7.8 | 0.3% | Aug 27, 2020 | A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in... |
| CVE-2020-3338 | HIGH | 7.5 | 1.8% | Aug 27, 2020 | A vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) of Cisco NX-OS Software cou... |
| CVE-2020-24705 | HIGH | 8.8 | 1.1% | Aug 27, 2020 | An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an att... |
| CVE-2020-24703 | HIGH | 8.8 | 1.1% | Aug 27, 2020 | An issue was discovered in certain WSO2 products. A valid Carbon Management Console session cookie may be sent to an att... |
| CVE-2020-23972 | HIGH | 7.5 | 31.4% | Aug 27, 2020 | In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating ... |
| CVE-2020-4603 | HIGH | 7.2 | 0.8% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level re... |
| CVE-2020-4174 | HIGH | 7.5 | 1.0% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to ... |
| CVE-2020-4169 | HIGH | 7.5 | 1.0% | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to ... |
| CVE-2020-17376 | HIGH | 8.3 | 1.7% | Aug 26, 2020 | An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, a... |
| CVE-2020-15156 | HIGH | 8.1 | 0.6% | Aug 26, 2020 | In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a... |
| CVE-2020-12855 | HIGH | 8.8 | 2.2% | Aug 26, 2020 | A Host header injection vulnerability has been discovered in SecZetta NEProfile 3.3.11. Authenticated remote adversaries... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now