2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4262 | HIGH | 7.8 | 0.4% | May 14, 2020 | IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused b... |
| CVE-2020-4261 | HIGH | 7.8 | 0.4% | May 14, 2020 | IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused b... |
| CVE-2020-4258 | HIGH | 7.8 | 0.4% | May 14, 2020 | IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused b... |
| CVE-2020-4257 | HIGH | 7.8 | 0.4% | May 14, 2020 | IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused b... |
| CVE-2020-10626 | HIGH | 7.8 | 0.5% | May 14, 2020 | In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malici... |
| CVE-2020-5577 | HIGH | 8.8 | 1.7% | May 14, 2020 | Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) ... |
| CVE-2020-5576 | HIGH | 8.8 | 0.8% | May 14, 2020 | Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movab... |
| CVE-2020-11069 | HIGH | 8.8 | 0.7% | May 14, 2020 | In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and ... |
| CVE-2020-11067 | HIGH | 8.8 | 2.0% | May 14, 2020 | In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_U... |
| CVE-2020-2016 | HIGH | 7 | 0.6% | May 13, 2020 | A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root pri... |
| CVE-2020-2015 | HIGH | 8.8 | 1.9% | May 13, 2020 | A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or ... |
| CVE-2020-2014 | HIGH | 8.8 | 2.7% | May 13, 2020 | An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbit... |
| CVE-2020-2013 | HIGH | 8.8 | 0.6% | May 13, 2020 | A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an ... |
| CVE-2020-2012 | HIGH | 7.5 | 1.9% | May 13, 2020 | Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management se... |
| CVE-2020-2011 | HIGH | 7.5 | 1.8% | May 13, 2020 | An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for ... |
| CVE-2020-2010 | HIGH | 7.2 | 2.2% | May 13, 2020 | An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute ar... |
| CVE-2020-2009 | HIGH | 7.2 | 2.0% | May 13, 2020 | An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an au... |
| CVE-2020-2008 | HIGH | 7.2 | 2.8% | May 13, 2020 | An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated... |
| CVE-2020-2007 | HIGH | 7.2 | 2.2% | May 13, 2020 | An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to poten... |
| CVE-2020-2006 | HIGH | 8.8 | 1.9% | May 13, 2020 | A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated us... |
| CVE-2020-2002 | HIGH | 8.1 | 1.3% | May 13, 2020 | An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Al... |
| CVE-2020-1998 | HIGH | 8.8 | 0.9% | May 13, 2020 | An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of t... |
| CVE-2020-1714 | HIGH | 8.8 | 2.6% | May 13, 2020 | A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without typ... |
| CVE-2020-11073 | HIGH | 7.8 | 0.5% | May 13, 2020 | In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could... |
| CVE-2020-5407 | HIGH | 8.8 | 1.2% | May 13, 2020 | Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now