2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7451 | MEDIUM | 5.3 | 1.1% | Apr 28, 2020 | In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE... |
| CVE-2020-12430 | MEDIUM | 6.5 | 2.3% | Apr 28, 2020 | An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A... |
| CVE-2020-9482 | MEDIUM | 6.5 | 2.6% | Apr 28, 2020 | If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Regi... |
| CVE-2020-4329 | MEDIUM | 4.3 | 1.3% | Apr 28, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenti... |
| CVE-2020-1774 | MEDIUM | 4.9 | 0.9% | Apr 28, 2020 | When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore ... |
| CVE-2020-10944 | MEDIUM | 5.4 | 0.7% | Apr 28, 2020 | HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a ... |
| CVE-2020-10094 | MEDIUM | 5.4 | 0.7% | Apr 28, 2020 | A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x befo... |
| CVE-2020-10093 | MEDIUM | 5.4 | 0.7% | Apr 28, 2020 | A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products. |
| CVE-2020-12286 | MEDIUM | 4.3 | 1.0% | Apr 28, 2020 | In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. Fo... |
| CVE-2020-5570 | MEDIUM | 5.4 | 0.8% | Apr 28, 2020 | Cross-site scripting vulnerability in Sales Force Assistant version 11.2.48 and earlier allows remote authenticated atta... |
| CVE-2020-5568 | MEDIUM | 6.1 | 0.8% | Apr 28, 2020 | Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 5.0.0 allows remote attackers to inject arbitrary web scrip... |
| CVE-2020-5566 | MEDIUM | 4.3 | 1.1% | Apr 28, 2020 | Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the... |
| CVE-2020-5565 | MEDIUM | 4.3 | 0.8% | Apr 28, 2020 | Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter... |
| CVE-2020-5564 | MEDIUM | 6.1 | 0.8% | Apr 28, 2020 | Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to inject arbitrary web scri... |
| CVE-2020-5563 | MEDIUM | 5.3 | 1.2% | Apr 28, 2020 | Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in the aff... |
| CVE-2020-5562 | MEDIUM | 4.9 | 0.9% | Apr 28, 2020 | Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an admini... |
| CVE-2020-1722 | MEDIUM | 5.3 | 1.0% | Apr 27, 2020 | A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to... |
| CVE-2020-1880 | MEDIUM | 5.5 | 0.5% | Apr 27, 2020 | Huawei smartphone Lion-AL00C with versions earlier than 10.0.0.205(C00E202R7P2) have a denial of service vulnerability. ... |
| CVE-2020-9072 | MEDIUM | 6.7 | 0.2% | Apr 27, 2020 | Huawei OSD product with versions earlier than OSD_uwp_9.0.32.0 have a local privilege escalation vulnerability. An authe... |
| CVE-2020-1845 | MEDIUM | 6.7 | 0.2% | Apr 27, 2020 | Huawei PCManager product with versions earlier than 10.0.5.53 have a local privilege escalation vulnerability. An authen... |
| CVE-2020-11822 | MEDIUM | 6.1 | 0.8% | Apr 27, 2020 | In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus... |
| CVE-2020-11821 | MEDIUM | 5.3 | 1.1% | Apr 27, 2020 | In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hash... |
| CVE-2020-11415 | MEDIUM | 4.9 | 0.6% | Apr 27, 2020 | An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can r... |
| CVE-2020-9489 | MEDIUM | 5.5 | 2.5% | Apr 27, 2020 | A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can a... |
| CVE-2020-12272 | MEDIUM | 5.3 | 2.1% | Apr 27, 2020 | OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now