2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-0535MEDIUM5.3Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthent...
CVE-2020-0533MEDIUM6.7Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to p...
CVE-2020-0531MEDIUM6.5Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an authentic...
CVE-2020-0527MEDIUM4.4Insufficient control flow management in firmware for some Intel(R) Data Center SSDs may allow a privileged user to poten...
CVE-2020-14093MEDIUM5.9Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
CVE-2020-11839MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to ...
CVE-2020-11980MEDIUM6.3In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "...
CVE-2020-4048MEDIUM5.7In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external...
CVE-2020-4047MEDIUM6.8In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScr...
CVE-2020-4046MEDIUM5.4In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in ...
CVE-2020-9651MEDIUM6.1Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (reflected) vulnerability. Successful expl...
CVE-2020-9648MEDIUM6.1Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation cou...
CVE-2020-9647MEDIUM6.1Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (dom-based) vulnerability. Successful expl...
CVE-2020-9644MEDIUM5.4Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (stored) vulnerability. Successful exploit...
CVE-2020-10732MEDIUM4.4A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local...
CVE-2020-4251MEDIUM5.4IBM API Connect 5.0.0.0 through 5.0.8.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2020-3929MEDIUM5.9GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may c...
CVE-2020-12797MEDIUM5.3HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to sec...
CVE-2020-12023MEDIUM4.5Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSi...
CVE-2020-0213MEDIUM6.5In hevcd_fmt_conv_420sp_to_420sp_av8 of ihevcd_fmt_conv_420sp_to_420sp.s, there is a possible out of bounds write due to...
CVE-2020-0212MEDIUM6.5In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use after free. This co...
CVE-2020-0211MEDIUM6.5In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a missing bounds check. ...
CVE-2020-0207MEDIUM6.5In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead t...
CVE-2020-0206MEDIUM5.5In the settings app, there is a possible app crash due to improper input validation. This could lead to local denial of ...
CVE-2020-0205MEDIUM6.5In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now