2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13817 | HIGH | 7.4 | 4.1% | Jun 4, 2020 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit o... |
| CVE-2020-13777 | HIGH | 7.4 | 17.5% | Jun 4, 2020 | GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS... |
| CVE-2020-6496 | HIGH | 8.8 | 1.4% | Jun 3, 2020 | Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perf... |
| CVE-2020-6453 | HIGH | 8.8 | 0.9% | Jun 3, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially expl... |
| CVE-2020-6419 | HIGH | 8.8 | 0.7% | Jun 3, 2020 | Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap c... |
| CVE-2020-11080 | HIGH | 7.5 | 5.3% | Jun 3, 2020 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of ... |
| CVE-2020-13790 | HIGH | 8.1 | 3.2% | Jun 3, 2020 | libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PP... |
| CVE-2020-13379 | HIGH | 8.2 | 99.9% | Jun 3, 2020 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows ... |
| CVE-2020-7014 | HIGH | 8.8 | 1.5% | Jun 3, 2020 | The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 cont... |
| CVE-2020-7013 | HIGH | 7.2 | 2.1% | Jun 3, 2020 | Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privil... |
| CVE-2020-7012 | HIGH | 8.8 | 18.2% | Jun 3, 2020 | Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authen... |
| CVE-2020-7010 | HIGH | 7.5 | 1.4% | Jun 3, 2020 | Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an... |
| CVE-2020-3281 | HIGH | 8.8 | 1.0% | Jun 3, 2020 | A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authent... |
| CVE-2020-3267 | HIGH | 7.1 | 0.8% | Jun 3, 2020 | A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated,... |
| CVE-2020-3257 | HIGH | 8.1 | 0.7% | Jun 3, 2020 | Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Ro... |
| CVE-2020-3238 | HIGH | 8.1 | 1.2% | Jun 3, 2020 | A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an aut... |
| CVE-2020-3235 | HIGH | 7.7 | 1.6% | Jun 3, 2020 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa... |
| CVE-2020-3234 | HIGH | 8.8 | 0.3% | Jun 3, 2020 | A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated ... |
| CVE-2020-3232 | HIGH | 7.7 | 1.0% | Jun 3, 2020 | A vulnerability in the Simple Network Management Protocol (SNMP) implementation in Cisco ASR 920 Series Aggregation Serv... |
| CVE-2020-3230 | HIGH | 7.5 | 1.7% | Jun 3, 2020 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software and Cisco IOS XE Sof... |
| CVE-2020-3229 | HIGH | 8.8 | 5.3% | Jun 3, 2020 | A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a ... |
| CVE-2020-3228 | HIGH | 8.6 | 1.8% | Jun 3, 2020 | A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX... |
| CVE-2020-3226 | HIGH | 8.6 | 1.6% | Jun 3, 2020 | A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS XE Software could a... |
| CVE-2020-3225 | HIGH | 8.6 | 2.1% | Jun 3, 2020 | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature of Cisco IOS Software and... |
| CVE-2020-3224 | HIGH | 8.8 | 1.8% | Jun 3, 2020 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now