2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1633 | MEDIUM | 6.5 | 0.5% | Apr 9, 2020 | Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Ju... |
| CVE-2020-8834 | MEDIUM | 6.5 | 0.3% | Apr 9, 2020 | KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entr... |
| CVE-2020-7922 | MEDIUM | 6.5 | 0.7% | Apr 9, 2020 | X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kube... |
| CVE-2020-5263 | MEDIUM | 4.9 | 0.9% | Apr 9, 2020 | auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of... |
| CVE-2020-9500 | MEDIUM | 4.9 | 1.0% | Apr 9, 2020 | Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the atta... |
| CVE-2020-10623 | MEDIUM | 6.5 | 0.9% | Apr 9, 2020 | Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions... |
| CVE-2020-11556 | MEDIUM | 5.4 | 0.6% | Apr 9, 2020 | An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) a... |
| CVE-2020-2732 | MEDIUM | 6.8 | 0.9% | Apr 8, 2020 | A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtu... |
| CVE-2020-1637 | MEDIUM | 6.5 | 0.8% | Apr 8, 2020 | A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to acces... |
| CVE-2020-1630 | MEDIUM | 5.5 | 0.2% | Apr 8, 2020 | A privilege escalation vulnerability in Juniper Networks Junos OS devices configured with dual Routing Engines (RE), Vir... |
| CVE-2020-1629 | MEDIUM | 5.9 | 0.7% | Apr 8, 2020 | A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process t... |
| CVE-2020-1628 | MEDIUM | 5.3 | 1.3% | Apr 8, 2020 | Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discov... |
| CVE-2020-1625 | MEDIUM | 6.5 | 0.8% | Apr 8, 2020 | The kernel memory usage represented as "temp" via 'show system virtual-memory' may constantly increase when Integrated R... |
| CVE-2020-1624 | MEDIUM | 5.5 | 0.3% | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon... |
| CVE-2020-1623 | MEDIUM | 5.5 | 0.3% | Apr 8, 2020 | A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. T... |
| CVE-2020-1622 | MEDIUM | 5.5 | 0.3% | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSha... |
| CVE-2020-1621 | MEDIUM | 5.5 | 0.3% | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue af... |
| CVE-2020-1620 | MEDIUM | 5.5 | 0.3% | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This is... |
| CVE-2020-1619 | MEDIUM | 6.7 | 0.3% | Apr 8, 2020 | A privilege escalation vulnerability in Juniper Networks QFX10K Series, EX9200 Series, MX Series, and PTX Series with Ne... |
| CVE-2020-1618 | MEDIUM | 6.8 | 0.3% | Apr 8, 2020 | On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console ... |
| CVE-2020-1616 | MEDIUM | 5.3 | 1.4% | Apr 8, 2020 | Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Net... |
| CVE-2020-1988 | MEDIUM | 6.7 | 0.4% | Apr 8, 2020 | An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user ... |
| CVE-2020-1986 | MEDIUM | 5.5 | 0.3% | Apr 8, 2020 | Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data'... |
| CVE-2020-1978 | MEDIUM | 4.4 | 0.3% | Apr 8, 2020 | TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high ... |
| CVE-2020-10981 | MEDIUM | 4.3 | 0.7% | Apr 8, 2020 | GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now