2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3252 | MEDIUM | 6.5 | 5.3% | Apr 15, 2020 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r... |
| CVE-2020-11660 | MEDIUM | 6.5 | 1.4% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricte... |
| CVE-2020-11659 | MEDIUM | 4.3 | 0.9% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a rest... |
| CVE-2020-11665 | MEDIUM | 6.1 | 1.6% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attac... |
| CVE-2020-11664 | MEDIUM | 6.1 | 1.4% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attack... |
| CVE-2020-11663 | MEDIUM | 6.1 | 1.3% | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform ... |
| CVE-2020-10951 | MEDIUM | 4.7 | 0.9% | Apr 15, 2020 | Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages. |
| CVE-2020-5346 | MEDIUM | 4.8 | 0.6% | Apr 15, 2020 | RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security... |
| CVE-2020-3954 | MEDIUM | 6.1 | 0.8% | Apr 15, 2020 | Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. |
| CVE-2020-3953 | MEDIUM | 4.8 | 0.7% | Apr 15, 2020 | Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input vali... |
| CVE-2020-11791 | MEDIUM | 6.1 | 0.6% | Apr 15, 2020 | NETGEAR JGS516PE devices before 2.6.0.43 are affected by reflected XSS. |
| CVE-2020-11787 | MEDIUM | 4.8 | 0.4% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-6992 | MEDIUM | 6.7 | 0.4% | Apr 15, 2020 | A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and ... |
| CVE-2020-11786 | MEDIUM | 4.8 | 0.5% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-11785 | MEDIUM | 4.8 | 0.4% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-11784 | MEDIUM | 4.8 | 0.4% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
| CVE-2020-10637 | MEDIUM | 5.5 | 0.8% | Apr 15, 2020 | Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted... |
| CVE-2020-0576 | MEDIUM | 6.5 | 0.5% | Apr 15, 2020 | Buffer overflow in Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially ... |
| CVE-2020-0568 | MEDIUM | 4.7 | 0.4% | Apr 15, 2020 | Race condition in the Intel(R) Driver and Support Assistant before version 20.1.5 may allow an authenticated user to pot... |
| CVE-2020-0558 | MEDIUM | 6.5 | 0.6% | Apr 15, 2020 | Improper buffer restrictions in kernel mode driver for Intel(R) PROSet/Wireless WiFi products before version 21.70 on Wi... |
| CVE-2020-4294 | MEDIUM | 6.3 | 1.2% | Apr 15, 2020 | IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated a... |
| CVE-2020-4274 | MEDIUM | 5.4 | 0.9% | Apr 15, 2020 | IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due ... |
| CVE-2020-4271 | MEDIUM | 6.3 | 1.7% | Apr 15, 2020 | IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be e... |
| CVE-2020-4268 | MEDIUM | 5.4 | 0.6% | Apr 15, 2020 | IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2020-11783 | MEDIUM | 4.8 | 0.5% | Apr 15, 2020 | Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 b... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now