2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10930 | MEDIUM | 6.5 | 0.9% | Jul 28, 2020 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG... |
| CVE-2020-15863 | MEDIUM | 5.3 | 0.5% | Jul 28, 2020 | hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during pack... |
| CVE-2020-15408 | MEDIUM | 4.6 | 0.8% | Jul 28, 2020 | An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admi... |
| CVE-2020-13913 | MEDIUM | 6.1 | 1.3% | Jul 28, 2020 | An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript... |
| CVE-2020-15712 | MEDIUM | 4.3 | 1.6% | Jul 28, 2020 | rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send ... |
| CVE-2020-4465 | MEDIUM | 6.5 | 1.9% | Jul 28, 2020 | IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnera... |
| CVE-2020-4319 | MEDIUM | 4.3 | 0.7% | Jul 28, 2020 | IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, a... |
| CVE-2020-4318 | MEDIUM | 5.4 | 0.6% | Jul 28, 2020 | IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operation... |
| CVE-2020-4317 | MEDIUM | 5.4 | 0.6% | Jul 28, 2020 | IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operation... |
| CVE-2020-12880 | MEDIUM | 5.5 | 0.5% | Jul 27, 2020 | An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By m... |
| CVE-2020-10643 | MEDIUM | 5.4 | 1.0% | Jul 27, 2020 | An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vuln... |
| CVE-2020-7017 | MEDIUM | 6.7 | 1.2% | Jul 27, 2020 | In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who i... |
| CVE-2020-7016 | MEDIUM | 4.8 | 1.1% | Jul 27, 2020 | Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a ... |
| CVE-2020-15120 | MEDIUM | 4.9 | 1.0% | Jul 27, 2020 | In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another ... |
| CVE-2020-4498 | MEDIUM | 4.4 | 0.3% | Jul 27, 2020 | IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inc... |
| CVE-2020-4408 | MEDIUM | 4.6 | 0.3% | Jul 27, 2020 | The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords duri... |
| CVE-2020-4405 | MEDIUM | 4.3 | 0.9% | Jul 27, 2020 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due t... |
| CVE-2020-11110 | MEDIUM | 5.4 | 9.6% | Jul 27, 2020 | Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an a... |
| CVE-2020-7695 | MEDIUM | 5.3 | 1.3% | Jul 27, 2020 | Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP head... |
| CVE-2020-15954 | MEDIUM | 6.5 | 0.7% | Jul 27, 2020 | KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encrypt... |
| CVE-2020-10614 | MEDIUM | 4.8 | 0.9% | Jul 25, 2020 | In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision dat... |
| CVE-2020-10602 | MEDIUM | 5.3 | 0.9% | Jul 24, 2020 | In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due... |
| CVE-2020-8175 | MEDIUM | 5.5 | 1.1% | Jul 24, 2020 | Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using... |
| CVE-2020-15945 | MEDIUM | 5.5 | 0.5% | Jul 24, 2020 | Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) bec... |
| CVE-2020-14725 | MEDIUM | 4.9 | 1.8% | Jul 24, 2020 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now