2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0127 | MEDIUM | 6.5 | 0.8% | Jun 11, 2020 | In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This cou... |
| CVE-2020-0126 | MEDIUM | 6.4 | 0.1% | Jun 11, 2020 | In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to l... |
| CVE-2020-0124 | MEDIUM | 6.7 | 0.1% | Jun 11, 2020 | In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check.... |
| CVE-2020-4380 | MEDIUM | 5.4 | 0.6% | Jun 11, 2020 | IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary... |
| CVE-2020-5592 | MEDIUM | 6.1 | 0.8% | Jun 11, 2020 | Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary Ja... |
| CVE-2020-13853 | MEDIUM | 5.4 | 1.0% | Jun 11, 2020 | Artica Pandora FMS 7.44 has persistent XSS in the Messages feature. |
| CVE-2020-13998 | MEDIUM | 5.3 | 1.4% | Jun 11, 2020 | Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on t... |
| CVE-2020-12714 | MEDIUM | 5.9 | 1.0% | Jun 11, 2020 | An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual A... |
| CVE-2020-5363 | MEDIUM | 6.7 | 0.3% | Jun 10, 2020 | Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed ... |
| CVE-2020-5362 | MEDIUM | 4.4 | 0.3% | Jun 10, 2020 | Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability ... |
| CVE-2020-13444 | MEDIUM | 6.5 | 1.6% | Jun 10, 2020 | Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack... |
| CVE-2020-2033 | MEDIUM | 5.3 | 0.8% | Jun 10, 2020 | When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can di... |
| CVE-2020-2023 | MEDIUM | 6.3 | 1.1% | Jun 10, 2020 | Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can ... |
| CVE-2020-14012 | MEDIUM | 5.4 | 0.5% | Jun 10, 2020 | scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker... |
| CVE-2020-14010 | MEDIUM | 6.1 | 0.9% | Jun 10, 2020 | The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parame... |
| CVE-2020-11798 | MEDIUM | 5.3 | 45.2% | Jun 10, 2020 | A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before ... |
| CVE-2020-0121 | MEDIUM | 5.5 | 0.3% | Jun 10, 2020 | In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead... |
| CVE-2020-0119 | MEDIUM | 5.3 | 0.7% | Jun 10, 2020 | In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle att... |
| CVE-2020-0116 | MEDIUM | 5.5 | 0.2% | Jun 10, 2020 | In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a... |
| CVE-2020-0113 | MEDIUM | 5.5 | 0.4% | Jun 10, 2020 | In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This cou... |
| CVE-2020-7580 | MEDIUM | 6.7 | 0.4% | Jun 10, 2020 | A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All... |
| CVE-2020-10755 | MEDIUM | 6.5 | 1.2% | Jun 10, 2020 | An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-ci... |
| CVE-2020-13271 | MEDIUM | 6.1 | 1.5% | Jun 10, 2020 | A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all p... |
| CVE-2020-13269 | MEDIUM | 6.1 | 1.8% | Jun 10, 2020 | A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Edi... |
| CVE-2020-13268 | MEDIUM | 5.3 | 1.1% | Jun 10, 2020 | A specially crafted request could be used to confirm the existence of files hosted on object storage services, without d... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now