2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0100 | MEDIUM | 5.5 | 0.1% | May 14, 2020 | In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to l... |
| CVE-2020-0093 | MEDIUM | 5 | 0.3% | May 14, 2020 | In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This ... |
| CVE-2020-0092 | MEDIUM | 5 | 0.1% | May 14, 2020 | In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification cont... |
| CVE-2020-0091 | MEDIUM | 5.5 | 0.1% | May 14, 2020 | In mnld, an incorrect configuration in driver_cfg of mnld for meta factory mode.Product: AndroidVersions: Android SoCAnd... |
| CVE-2020-0090 | MEDIUM | 5.5 | 0.1% | May 14, 2020 | An improper authorization in the receiver component of Email.Product: AndroidVersions: Android SoCAndroid ID: A-14981304... |
| CVE-2020-0065 | MEDIUM | 5.5 | 0.1% | May 14, 2020 | An improper authorization in the receiver component of the Android Suite Daemon.Product: AndroidVersions: Android SoCAnd... |
| CVE-2020-0064 | MEDIUM | 5.5 | 0.1% | May 14, 2020 | An improper authorization while processing the provisioning data.Product: AndroidVersions: Android SoCAndroid ID: A-1498... |
| CVE-2020-12875 | MEDIUM | 6.3 | 0.6% | May 14, 2020 | Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain un... |
| CVE-2020-5408 | MEDIUM | 6.5 | 1.8% | May 14, 2020 | Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.... |
| CVE-2020-12677 | MEDIUM | 6.1 | 1.9% | May 14, 2020 | An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately s... |
| CVE-2020-1960 | MEDIUM | 4.7 | 0.9% | May 14, 2020 | A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 t... |
| CVE-2020-1941 | MEDIUM | 6.1 | 6.2% | May 14, 2020 | In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a q... |
| CVE-2020-4365 | MEDIUM | 4.3 | 1.4% | May 14, 2020 | IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted reques... |
| CVE-2020-4299 | MEDIUM | 4.3 | 1.0% | May 14, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user throug... |
| CVE-2020-4259 | MEDIUM | 6.5 | 0.8% | May 14, 2020 | IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information ... |
| CVE-2020-1945 | MEDIUM | 6.3 | 1.8% | May 14, 2020 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system propert... |
| CVE-2020-12717 | MEDIUM | 6.5 | 1.4% | May 14, 2020 | The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere ... |
| CVE-2020-5575 | MEDIUM | 6.1 | 0.9% | May 14, 2020 | Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), M... |
| CVE-2020-5574 | MEDIUM | 5.3 | 1.2% | May 14, 2020 | HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable ... |
| CVE-2020-5409 | MEDIUM | 6.1 | 0.9% | May 14, 2020 | Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unau... |
| CVE-2020-11065 | MEDIUM | 5.4 | 0.5% | May 13, 2020 | In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.... |
| CVE-2020-11064 | MEDIUM | 5.4 | 0.5% | May 13, 2020 | In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.... |
| CVE-2020-2017 | MEDIUM | 6.1 | 0.8% | May 13, 2020 | A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacke... |
| CVE-2020-2005 | MEDIUM | 6.1 | 0.8% | May 13, 2020 | A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalPro... |
| CVE-2020-2004 | MEDIUM | 5.5 | 0.3% | May 13, 2020 | Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now