2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0535 | MEDIUM | 5.3 | 1.6% | Jun 15, 2020 | Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthent... |
| CVE-2020-0533 | MEDIUM | 6.7 | 0.2% | Jun 15, 2020 | Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to p... |
| CVE-2020-0531 | MEDIUM | 6.5 | 1.4% | Jun 15, 2020 | Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an authentic... |
| CVE-2020-0527 | MEDIUM | 4.4 | 0.3% | Jun 15, 2020 | Insufficient control flow management in firmware for some Intel(R) Data Center SSDs may allow a privileged user to poten... |
| CVE-2020-14093 | MEDIUM | 5.9 | 2.1% | Jun 15, 2020 | Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. |
| CVE-2020-11839 | MEDIUM | 6.1 | 0.6% | Jun 12, 2020 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to ... |
| CVE-2020-11980 | MEDIUM | 6.3 | 1.9% | Jun 12, 2020 | In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "... |
| CVE-2020-4048 | MEDIUM | 5.7 | 2.3% | Jun 12, 2020 | In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external... |
| CVE-2020-4047 | MEDIUM | 6.8 | 3.6% | Jun 12, 2020 | In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScr... |
| CVE-2020-4046 | MEDIUM | 5.4 | 2.4% | Jun 12, 2020 | In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in ... |
| CVE-2020-9651 | MEDIUM | 6.1 | 2.4% | Jun 12, 2020 | Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (reflected) vulnerability. Successful expl... |
| CVE-2020-9648 | MEDIUM | 6.1 | 2.4% | Jun 12, 2020 | Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation cou... |
| CVE-2020-9647 | MEDIUM | 6.1 | 2.4% | Jun 12, 2020 | Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (dom-based) vulnerability. Successful expl... |
| CVE-2020-9644 | MEDIUM | 5.4 | 1.8% | Jun 12, 2020 | Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (stored) vulnerability. Successful exploit... |
| CVE-2020-10732 | MEDIUM | 4.4 | 0.6% | Jun 12, 2020 | A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local... |
| CVE-2020-4251 | MEDIUM | 5.4 | 0.6% | Jun 12, 2020 | IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2020-3929 | MEDIUM | 5.9 | 0.5% | Jun 12, 2020 | GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may c... |
| CVE-2020-12797 | MEDIUM | 5.3 | 1.6% | Jun 11, 2020 | HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to sec... |
| CVE-2020-12023 | MEDIUM | 4.5 | 0.5% | Jun 11, 2020 | Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSi... |
| CVE-2020-0213 | MEDIUM | 6.5 | 0.9% | Jun 11, 2020 | In hevcd_fmt_conv_420sp_to_420sp_av8 of ihevcd_fmt_conv_420sp_to_420sp.s, there is a possible out of bounds write due to... |
| CVE-2020-0212 | MEDIUM | 6.5 | 0.7% | Jun 11, 2020 | In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use after free. This co... |
| CVE-2020-0211 | MEDIUM | 6.5 | 0.7% | Jun 11, 2020 | In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a missing bounds check. ... |
| CVE-2020-0207 | MEDIUM | 6.5 | 0.7% | Jun 11, 2020 | In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead t... |
| CVE-2020-0206 | MEDIUM | 5.5 | 0.1% | Jun 11, 2020 | In the settings app, there is a possible app crash due to improper input validation. This could lead to local denial of ... |
| CVE-2020-0205 | MEDIUM | 6.5 | 0.7% | Jun 11, 2020 | In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now