2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14470 | MEDIUM | 6.5 | 0.9% | Jun 19, 2020 | In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that l... |
| CVE-2020-14460 | MEDIUM | 6.5 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAu... |
| CVE-2020-14457 | MEDIUM | 5.3 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the upd... |
| CVE-2020-14455 | MEDIUM | 6.5 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, a... |
| CVE-2020-14454 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application ... |
| CVE-2020-14452 | MEDIUM | 5.3 | 1.3% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-001... |
| CVE-2020-14462 | MEDIUM | 5.4 | 0.6% | Jun 19, 2020 | CALDERA 2.7.0 allows XSS via the Operation Name box. |
| CVE-2020-14446 | MEDIUM | 6.1 | 0.8% | Jun 18, 2020 | An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redire... |
| CVE-2020-14445 | MEDIUM | 5.4 | 0.6% | Jun 18, 2020 | An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Refl... |
| CVE-2020-14444 | MEDIUM | 5.4 | 0.7% | Jun 18, 2020 | An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Refl... |
| CVE-2020-13882 | MEDIUM | 4.2 | 0.3% | Jun 18, 2020 | CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log ... |
| CVE-2020-14434 | MEDIUM | 6.8 | 0.8% | Jun 18, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.15.25... |
| CVE-2020-14433 | MEDIUM | 6.8 | 0.7% | Jun 18, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.15.25... |
| CVE-2020-1835 | MEDIUM | 6.5 | 0.4% | Jun 18, 2020 | HUAWEI Mate 30 with versions earlier than 10.1.0.126(C00E125R5P3) have an information disclosure vulnerability. A logic ... |
| CVE-2020-1834 | MEDIUM | 4.6 | 0.1% | Jun 18, 2020 | HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C... |
| CVE-2020-14423 | MEDIUM | 5.3 | 1.1% | Jun 18, 2020 | Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictab... |
| CVE-2020-14422 | MEDIUM | 5.9 | 12.8% | Jun 18, 2020 | Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes,... |
| CVE-2020-10782 | MEDIUM | 6.5 | 0.3% | Jun 18, 2020 | An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and oth... |
| CVE-2020-14416 | MEDIUM | 4.2 | 0.3% | Jun 18, 2020 | In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline cou... |
| CVE-2020-3368 | MEDIUM | 5.8 | 1.4% | Jun 18, 2020 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)... |
| CVE-2020-3364 | MEDIUM | 5.3 | 0.9% | Jun 18, 2020 | A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Ci... |
| CVE-2020-3362 | MEDIUM | 4.7 | 0.2% | Jun 18, 2020 | A vulnerability in the CLI of Cisco Network Services Orchestrator (NSO) could allow an authenticated, local attacker to ... |
| CVE-2020-3360 | MEDIUM | 5.3 | 1.3% | Jun 18, 2020 | A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated,... |
| CVE-2020-3356 | MEDIUM | 6.1 | 0.8% | Jun 18, 2020 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe... |
| CVE-2020-3355 | MEDIUM | 4.8 | 0.6% | Jun 18, 2020 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now