2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8356 | MEDIUM | 4.9 | 0.5% | Mar 9, 2021 | An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, fo... |
| CVE-2020-35451 | MEDIUM | 4.7 | 0.4% | Mar 9, 2021 | There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to ... |
| CVE-2020-27838 | MEDIUM | 6.5 | 17.9% | Mar 8, 2021 | A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information a... |
| CVE-2020-27576 | MEDIUM | 5.4 | 0.6% | Mar 8, 2021 | Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web ap... |
| CVE-2020-27575 | HIGH | 8.8 | 4.6% | Mar 8, 2021 | Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functio... |
| CVE-2020-27574 | HIGH | 8.8 | 0.8% | Mar 8, 2021 | Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malic... |
| CVE-2020-5014 | MEDIUM | 6.7 | 0.9% | Mar 8, 2021 | IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary cod... |
| CVE-2020-4903 | MEDIUM | 6.5 | 0.7% | Mar 8, 2021 | IBM API Connect V10 and V2018 could allow an attacker who has intercepted a registration invitation link to impersonate ... |
| CVE-2020-4695 | HIGH | 7.5 | 0.8% | Mar 8, 2021 | IBM API Connect V10 is impacted by insecure communications during database replication. As the data replication happens ... |
| CVE-2020-27817 | — | — | — | Mar 8, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA |
| CVE-2020-23967 | HIGH | 7.8 | 0.3% | Mar 8, 2021 | Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges ... |
| CVE-2020-28466 | HIGH | 7.5 | 3.7% | Mar 7, 2021 | This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the ser... |
| CVE-2020-29030 | HIGH | 8.8 | 0.5% | Mar 5, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute maliciou... |
| CVE-2020-29029 | MEDIUM | 6.1 | 0.8% | Mar 5, 2021 | Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker... |
| CVE-2020-29028 | MEDIUM | 6.1 | 0.7% | Mar 5, 2021 | Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javasc... |
| CVE-2020-29020 | HIGH | 7.2 | 1.7% | Mar 5, 2021 | Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI ... |
| CVE-2020-28502 | HIGH | 8.1 | 4.6% | Mar 5, 2021 | This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are ... |
| CVE-2020-35594 | MEDIUM | 6.1 | 1.0% | Mar 5, 2021 | Zoho ManageEngine ADManager Plus before 7066 allows XSS. |
| CVE-2020-29032 | HIGH | 7.2 | 0.5% | Mar 5, 2021 | Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated att... |
| CVE-2020-28050 | CRITICAL | 9.1 | 5.0% | Mar 5, 2021 | Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to co... |
| CVE-2020-29134 | HIGH | 8.6 | 15.0% | Mar 5, 2021 | The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all v... |
| CVE-2020-29658 | CRITICAL | 9.8 | 3.7% | Mar 5, 2021 | Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to... |
| CVE-2020-5148 | HIGH | 8.2 | 0.8% | Mar 5, 2021 | SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing m... |
| CVE-2020-36255 | HIGH | 7.5 | 1.5% | Mar 5, 2021 | An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0. The Branca implementation allows a... |
| CVE-2020-25639 | MEDIUM | 4.4 | 0.4% | Mar 4, 2021 | A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now