2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-0058 | MEDIUM | 4.4 | 0.2% | Mar 10, 2020 | In l2c_rcv_acl_data of l2c_main.cc, there is a possible out of bounds read due to an incorrect bounds check. This could ... |
| CVE-2020-0044 | MEDIUM | 4.4 | 0.1% | Mar 10, 2020 | In set_nonce of fpc_ta_qc_auth.c, there is a possible out of bounds read due to a missing bounds check. This could lead ... |
| CVE-2020-0043 | MEDIUM | 4.4 | 0.2% | Mar 10, 2020 | In authorize_enrol of fpc_ta_hw_auth.c, there is a possible out of bounds read due to a missing bounds check. This could... |
| CVE-2020-0042 | MEDIUM | 4.4 | 0.2% | Mar 10, 2020 | In fpc_ta_hw_auth_unwrap_key of fpc_ta_hw_auth_qsee.c, there is a possible out of bounds read due to a missing bounds ch... |
| CVE-2020-0035 | MEDIUM | 5.5 | 0.2% | Mar 10, 2020 | In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This ... |
| CVE-2020-0031 | MEDIUM | 5 | 0.2% | Mar 10, 2020 | In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmented Autofill to displa... |
| CVE-2020-0012 | MEDIUM | 6.7 | 0.2% | Mar 10, 2020 | In fpc_ta_pn_get_unencrypted_image of fpc_ta_pn.c, there is a possible out of bounds write due to a missing bounds check... |
| CVE-2020-0011 | MEDIUM | 6.7 | 0.2% | Mar 10, 2020 | In get_auth_result of fpc_ta_hw_auth.c, there is a possible out of bounds write due to a missing bounds check. This coul... |
| CVE-2020-0010 | MEDIUM | 6.7 | 0.2% | Mar 10, 2020 | In fpc_ta_get_build_info of fpc_ta_kpi.c, there is a possible out of bounds write due to a missing bounds check. This co... |
| CVE-2020-9440 | MEDIUM | 6.1 | 1.3% | Mar 10, 2020 | A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to r... |
| CVE-2020-4162 | MEDIUM | 5.4 | 0.6% | Mar 10, 2020 | IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2020-10251 | MEDIUM | 5.5 | 1.5% | Mar 10, 2020 | In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c.... |
| CVE-2020-10249 | MEDIUM | 5.3 | 1.0% | Mar 9, 2020 | BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3. |
| CVE-2020-10247 | MEDIUM | 6.1 | 0.8% | Mar 9, 2020 | MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_... |
| CVE-2020-10246 | MEDIUM | 6.1 | 0.8% | Mar 9, 2020 | MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp. |
| CVE-2020-10192 | MEDIUM | 6.1 | 0.8% | Mar 9, 2020 | An issue was discovered in Munkireport before 5.3.0.3923. An unauthenticated actor can send a custom XSS payload through... |
| CVE-2020-10191 | MEDIUM | 5.4 | 0.6% | Mar 9, 2020 | An issue was discovered in MunkiReport before 5.3.0. An authenticated actor can send a custom XSS payload through the /m... |
| CVE-2020-4084 | MEDIUM | 5.4 | 0.5% | Mar 9, 2020 | HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2020-9517 | MEDIUM | 5.4 | 0.5% | Mar 9, 2020 | There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Co... |
| CVE-2020-9386 | MEDIUM | 4.3 | 1.0% | Mar 9, 2020 | In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed t... |
| CVE-2020-2157 | MEDIUM | 4.3 | 0.5% | Mar 9, 2020 | Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configurat... |
| CVE-2020-2156 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration ... |
| CVE-2020-2155 | MEDIUM | 5.3 | 0.6% | Mar 9, 2020 | Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global... |
| CVE-2020-2154 | MEDIUM | 5.5 | 0.3% | Mar 9, 2020 | Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configur... |
| CVE-2020-2153 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now