2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10930MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG...
CVE-2020-15863MEDIUM5.3hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during pack...
CVE-2020-15408MEDIUM4.6An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admi...
CVE-2020-13913MEDIUM6.1An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript...
CVE-2020-15712MEDIUM4.3rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send ...
CVE-2020-4465MEDIUM6.5IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnera...
CVE-2020-4319MEDIUM4.3IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, a...
CVE-2020-4318MEDIUM5.4IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operation...
CVE-2020-4317MEDIUM5.4IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operation...
CVE-2020-12880MEDIUM5.5An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By m...
CVE-2020-10643MEDIUM5.4An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vuln...
CVE-2020-7017MEDIUM6.7In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who i...
CVE-2020-7016MEDIUM4.8Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a ...
CVE-2020-15120MEDIUM4.9In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another ...
CVE-2020-4498MEDIUM4.4IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inc...
CVE-2020-4408MEDIUM4.6The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords duri...
CVE-2020-4405MEDIUM4.3IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due t...
CVE-2020-11110MEDIUM5.4Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an a...
CVE-2020-7695MEDIUM5.3Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP head...
CVE-2020-15954MEDIUM6.5KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encrypt...
CVE-2020-10614MEDIUM4.8In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision dat...
CVE-2020-10602MEDIUM5.3In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due...
CVE-2020-8175MEDIUM5.5Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using...
CVE-2020-15945MEDIUM5.5Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) bec...
CVE-2020-14725MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now