2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4757 | MEDIUM | 6.4 | 1.3% | Dec 21, 2020 | IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerab... |
| CVE-2020-4555 | MEDIUM | 5.4 | 0.8% | Dec 21, 2020 | IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenti... |
| CVE-2020-27254 | HIGH | 7.5 | 1.3% | Dec 21, 2020 | Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products a... |
| CVE-2020-26422 | MEDIUM | 5.3 | 4.7% | Dec 21, 2020 | Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted c... |
| CVE-2020-26275 | MEDIUM | 6.1 | 1.4% | Dec 21, 2020 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications ... |
| CVE-2020-25860 | MEDIUM | 6.6 | 1.4% | Dec 21, 2020 | The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerab... |
| CVE-2020-14225 | MEDIUM | 6.5 | 1.3% | Dec 21, 2020 | HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote una... |
| CVE-2020-35497 | MEDIUM | 6.5 | 0.8% | Dec 21, 2020 | A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal informat... |
| CVE-2020-26263 | HIGH | 7.5 | 1.3% | Dec 21, 2020 | tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before ve... |
| CVE-2020-17526 | HIGH | 7.7 | 23.3% | Dec 21, 2020 | Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a maliciou... |
| CVE-2020-3999 | MEDIUM | 6.5 | 0.3% | Dec 21, 2020 | VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware ... |
| CVE-2020-27846 | CRITICAL | 9.8 | 4.8% | Dec 21, 2020 | A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authenticatio... |
| CVE-2020-35276 | CRITICAL | 9.8 | 1.8% | Dec 21, 2020 | EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQ... |
| CVE-2020-35275 | MEDIUM | 5.4 | 1.0% | Dec 21, 2020 | Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to an... |
| CVE-2020-35274 | MEDIUM | 4.8 | 0.6% | Dec 21, 2020 | DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attac... |
| CVE-2020-35273 | HIGH | 8 | 0.6% | Dec 21, 2020 | EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to ... |
| CVE-2020-26049 | MEDIUM | 6.1 | 1.3% | Dec 21, 2020 | Nifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution. |
| CVE-2020-35590 | CRITICAL | 9.8 | 4.3% | Dec 21, 2020 | LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per I... |
| CVE-2020-35589 | MEDIUM | 5.4 | 0.8% | Dec 21, 2020 | The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-logi... |
| CVE-2020-29447 | MEDIUM | 4.3 | 1.0% | Dec 21, 2020 | Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of ... |
| CVE-2020-35579 | HIGH | 7.5 | 1.1% | Dec 20, 2020 | tindy2013 subconverter 0.6.4 has a /sub?target=%TARGET%&url=%URL%&config=%CONFIG% API endpoint that accepts an arbitrary... |
| CVE-2020-35573 | HIGH | 7.5 | 2.7% | Dec 20, 2020 | srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timesta... |
| CVE-2020-7203 | CRITICAL | 9.8 | 5.0% | Dec 18, 2020 | A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability ... |
| CVE-2020-7201 | HIGH | 8.8 | 0.6% | Dec 18, 2020 | A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G... |
| CVE-2020-7200 | CRITICAL | 9.8 | 81.9% | Dec 18, 2020 | A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerabili... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now