2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6500 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof ... |
| CVE-2020-6499 | MEDIUM | 6.5 | 0.7% | Jun 3, 2020 | Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppC... |
| CVE-2020-6498 | MEDIUM | 6.5 | 0.9% | Jun 3, 2020 | Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to pe... |
| CVE-2020-6497 | MEDIUM | 6.5 | 0.8% | Jun 3, 2020 | Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to pe... |
| CVE-2020-6495 | MEDIUM | 6.5 | 1.1% | Jun 3, 2020 | Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convin... |
| CVE-2020-6494 | MEDIUM | 6.5 | 1.5% | Jun 3, 2020 | Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof t... |
| CVE-2020-11091 | MEDIUM | 5.8 | 0.9% | Jun 3, 2020 | In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS re... |
| CVE-2020-5299 | MEDIUM | 5.1 | 1.0% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to... |
| CVE-2020-5298 | MEDIUM | 4.8 | 0.9% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to us... |
| CVE-2020-5296 | MEDIUM | 4.9 | 1.4% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this ... |
| CVE-2020-5295 | MEDIUM | 4.9 | 7.4% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this ... |
| CVE-2020-13798 | MEDIUM | 6.1 | 0.7% | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/f... |
| CVE-2020-13797 | MEDIUM | 6.1 | 0.7% | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/w... |
| CVE-2020-13796 | MEDIUM | 6.1 | 0.7% | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/s... |
| CVE-2020-13795 | MEDIUM | 5.3 | 1.8% | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/temp... |
| CVE-2020-13792 | MEDIUM | 4.3 | 1.1% | Jun 3, 2020 | PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory tra... |
| CVE-2020-3353 | MEDIUM | 5.9 | 0.8% | Jun 3, 2020 | A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, ... |
| CVE-2020-3339 | MEDIUM | 5.4 | 1.1% | Jun 3, 2020 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote... |
| CVE-2020-7015 | MEDIUM | 5.4 | 0.8% | Jun 3, 2020 | Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to ... |
| CVE-2020-7011 | MEDIUM | 6.1 | 1.0% | Jun 3, 2020 | Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the ... |
| CVE-2020-3335 | MEDIUM | 5.5 | 0.3% | Jun 3, 2020 | A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attac... |
| CVE-2020-3333 | MEDIUM | 5.3 | 1.0% | Jun 3, 2020 | A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker... |
| CVE-2020-3237 | MEDIUM | 6.3 | 0.4% | Jun 3, 2020 | A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an aut... |
| CVE-2020-3233 | MEDIUM | 5.4 | 0.6% | Jun 3, 2020 | A vulnerability in the web-based Local Manager interface of the Cisco IOx Application Framework could allow an authentic... |
| CVE-2020-3231 | MEDIUM | 4.7 | 0.5% | Jun 3, 2020 | A vulnerability in the 802.1X feature of Cisco Catalyst 2960-L Series Switches and Cisco Catalyst CDB-8P Switches could ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now