2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15707 | MEDIUM | 6.4 | 1.6% | Jul 29, 2020 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRU... |
| CVE-2020-15706 | MEDIUM | 6.4 | 1.0% | Jul 29, 2020 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be ... |
| CVE-2020-15705 | MEDIUM | 6.4 | 1.4% | Jul 29, 2020 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This on... |
| CVE-2020-11934 | MEDIUM | 5.9 | 0.4% | Jul 29, 2020 | It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the syste... |
| CVE-2020-11933 | MEDIUM | 6.8 | 0.2% | Jul 29, 2020 | cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, ... |
| CVE-2020-8553 | MEDIUM | 5.9 | 0.9% | Jul 29, 2020 | The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and t... |
| CVE-2020-16095 | MEDIUM | 6.1 | 0.9% | Jul 29, 2020 | The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS. |
| CVE-2020-4645 | MEDIUM | 5.4 | 0.6% | Jul 29, 2020 | IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2020-4644 | MEDIUM | 5.4 | 1.2% | Jul 29, 2020 | IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the vi... |
| CVE-2020-4573 | MEDIUM | 5.3 | 1.3% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated... |
| CVE-2020-4572 | MEDIUM | 5.3 | 1.7% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a deta... |
| CVE-2020-4569 | MEDIUM | 6.5 | 1.2% | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an ... |
| CVE-2020-2078 | MEDIUM | 6.5 | 0.8% | Jul 29, 2020 | Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1... |
| CVE-2020-9692 | MEDIUM | 6.5 | 3.8% | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Success... |
| CVE-2020-9690 | MEDIUM | 4.2 | 1.6% | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Suc... |
| CVE-2020-9689 | MEDIUM | 6.5 | 4.1% | Jul 29, 2020 | Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploita... |
| CVE-2020-14492 | MEDIUM | 6.1 | 1.2% | Jul 29, 2020 | OpenClinic GA 5.09.02 and 5.89.05b does not properly neutralize user-controllable input, which may allow the execution o... |
| CVE-2020-5614 | MEDIUM | 5.3 | 2.2% | Jul 29, 2020 | Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unsp... |
| CVE-2020-5613 | MEDIUM | 6.1 | 1.1% | Jul 29, 2020 | Cross-site scripting vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to execute an arbitrary script ... |
| CVE-2020-5612 | MEDIUM | 6.1 | 1.1% | Jul 29, 2020 | Cross-site scripting vulnerability in KonaWiki 2.2.0 and earlier allows remote attackers to execute an arbitrary script ... |
| CVE-2020-13971 | MEDIUM | 5.4 | 0.6% | Jul 28, 2020 | In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG image... |
| CVE-2020-10985 | MEDIUM | 4.8 | 0.6% | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php. |
| CVE-2020-10983 | MEDIUM | 4.9 | 1.4% | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php. |
| CVE-2020-10982 | MEDIUM | 4.9 | 1.4% | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php. |
| CVE-2020-15417 | MEDIUM | 6.3 | 1.3% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now