2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9603 | MEDIUM | 5.5 | 2.8% | Jun 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an... |
| CVE-2020-9602 | MEDIUM | 5.5 | 2.8% | Jun 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an... |
| CVE-2020-9598 | MEDIUM | 5.5 | 2.8% | Jun 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an... |
| CVE-2020-9595 | MEDIUM | 5.5 | 2.8% | Jun 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an... |
| CVE-2020-9593 | MEDIUM | 5.5 | 2.8% | Jun 25, 2020 | Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, an... |
| CVE-2020-5967 | MEDIUM | 4.7 | 0.3% | Jun 25, 2020 | NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may... |
| CVE-2020-9666 | MEDIUM | 5.5 | 2.4% | Jun 25, 2020 | Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to infor... |
| CVE-2020-9437 | MEDIUM | 4.8 | 1.0% | Jun 25, 2020 | SecureAuth.aspx in SecureAuth IdP 9.3.0 suffers from a client-side template injection that allows for script execution, ... |
| CVE-2020-4072 | MEDIUM | 5.3 | 1.2% | Jun 25, 2020 | In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is ... |
| CVE-2020-10994 | MEDIUM | 5.5 | 1.4% | Jun 25, 2020 | In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file. |
| CVE-2020-10378 | MEDIUM | 5.5 | 1.1% | Jun 25, 2020 | In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->sh... |
| CVE-2020-10177 | MEDIUM | 5.5 | 1.5% | Jun 25, 2020 | Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c. |
| CVE-2020-7355 | MEDIUM | 6.1 | 0.9% | Jun 25, 2020 | Cross-site Scripting (XSS) vulnerability in the 'notes' field of a discovered scan asset in Rapid7 Metasploit Pro allows... |
| CVE-2020-7354 | MEDIUM | 5.4 | 0.9% | Jun 25, 2020 | Cross-site Scripting (XSS) vulnerability in the 'host' field of a discovered scan asset in Rapid7 Metasploit Pro allows ... |
| CVE-2020-3971 | MEDIUM | 5.5 | 0.3% | Jun 25, 2020 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and... |
| CVE-2020-3965 | MEDIUM | 5.5 | 0.6% | Jun 25, 2020 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), ... |
| CVE-2020-3964 | MEDIUM | 4.7 | 0.5% | Jun 25, 2020 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), ... |
| CVE-2020-3963 | MEDIUM | 5.5 | 0.5% | Jun 25, 2020 | VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), ... |
| CVE-2020-11735 | MEDIUM | 5.3 | 1.3% | Jun 25, 2020 | The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to a... |
| CVE-2020-15047 | MEDIUM | 5.9 | 0.8% | Jun 25, 2020 | MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to ... |
| CVE-2020-5965 | MEDIUM | 5.5 | 0.3% | Jun 25, 2020 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x... |
| CVE-2020-15041 | MEDIUM | 4.8 | 0.5% | Jun 24, 2020 | PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field. |
| CVE-2020-15038 | MEDIUM | 5.4 | 3.8% | Jun 24, 2020 | The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS. |
| CVE-2020-15026 | MEDIUM | 4.9 | 1.3% | Jun 24, 2020 | Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file do... |
| CVE-2020-15025 | MEDIUM | 4.9 | 3.4% | Jun 24, 2020 | ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now