2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10859 | MEDIUM | 6.5 | 4.4% | May 5, 2020 | Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extracti... |
| CVE-2020-10630 | MEDIUM | 6.1 | 0.7% | May 5, 2020 | SAE IT-systems FW-50 Remote Telemetry Unit (RTU). The software does not neutralize or incorrectly neutralizes user-contr... |
| CVE-2020-12144 | MEDIUM | 4.9 | 0.3% | May 5, 2020 | The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it pos... |
| CVE-2020-12143 | MEDIUM | 4.9 | 0.3% | May 5, 2020 | The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someo... |
| CVE-2020-12142 | MEDIUM | 4.9 | 0.7% | May 5, 2020 | 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user ... |
| CVE-2020-8033 | MEDIUM | 6.1 | 0.7% | May 5, 2020 | Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field. |
| CVE-2020-5517 | MEDIUM | 6.5 | 0.6% | May 5, 2020 | CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analys... |
| CVE-2020-8799 | MEDIUM | 4.8 | 0.7% | May 5, 2020 | A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordP... |
| CVE-2020-11737 | MEDIUM | 6.1 | 1.7% | May 5, 2020 | A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-M... |
| CVE-2020-12659 | MEDIUM | 6.7 | 0.7% | May 5, 2020 | An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write ... |
| CVE-2020-12656 | MEDIUM | 5.5 | 0.3% | May 5, 2020 | gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through... |
| CVE-2020-12655 | MEDIUM | 5.5 | 0.5% | May 5, 2020 | An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may... |
| CVE-2020-12652 | MEDIUM | 4.1 | 0.3% | May 5, 2020 | The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to h... |
| CVE-2020-10717 | MEDIUM | 6.5 | 0.4% | May 4, 2020 | A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version... |
| CVE-2020-10700 | MEDIUM | 5.3 | 2.0% | May 4, 2020 | A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with th... |
| CVE-2020-10686 | MEDIUM | 4.7 | 0.7% | May 4, 2020 | A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user re... |
| CVE-2020-8896 | MEDIUM | 5.9 | 0.4% | May 4, 2020 | A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 all... |
| CVE-2020-5337 | MEDIUM | 6.1 | 0.8% | May 4, 2020 | RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attack... |
| CVE-2020-5336 | MEDIUM | 6.1 | 0.7% | May 4, 2020 | RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could... |
| CVE-2020-5334 | MEDIUM | 6.1 | 0.9% | May 4, 2020 | RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulner... |
| CVE-2020-5333 | MEDIUM | 4.3 | 0.8% | May 4, 2020 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote ... |
| CVE-2020-5331 | MEDIUM | 5.5 | 0.7% | May 4, 2020 | RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session informatio... |
| CVE-2020-10618 | MEDIUM | 5.5 | 0.8% | May 4, 2020 | LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unau... |
| CVE-2020-1732 | MEDIUM | 4.2 | 0.7% | May 4, 2020 | A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identi... |
| CVE-2020-10933 | MEDIUM | 5.3 | 2.6% | May 4, 2020 | An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now