2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10007 | MEDIUM | 5.5 | 0.4% | Dec 8, 2020 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A malicious app... |
| CVE-2020-10006 | MEDIUM | 5.5 | 0.9% | Dec 8, 2020 | This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.0.1. A malicious applicatio... |
| CVE-2020-10004 | HIGH | 7.8 | 1.1% | Dec 8, 2020 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iP... |
| CVE-2020-10003 | HIGH | 7.8 | 0.4% | Dec 8, 2020 | An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization... |
| CVE-2020-10002 | MEDIUM | 5.5 | 0.4% | Dec 8, 2020 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iO... |
| CVE-2020-29602 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System us... |
| CVE-2020-29601 | CRITICAL | 9.8 | 2.3% | Dec 8, 2020 | The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notar... |
| CVE-2020-29581 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped d... |
| CVE-2020-29580 | CRITICAL | 9.8 | 2.3% | Dec 8, 2020 | The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker c... |
| CVE-2020-29579 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Exp... |
| CVE-2020-29577 | CRITICAL | 9.8 | 2.3% | Dec 8, 2020 | The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker ... |
| CVE-2020-29576 | CRITICAL | 9.8 | 3.0% | Dec 8, 2020 | The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop D... |
| CVE-2020-29575 | CRITICAL | 9.8 | 2.9% | Dec 8, 2020 | The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. System... |
| CVE-2020-29564 | CRITICAL | 9.8 | 6.2% | Dec 8, 2020 | The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul ... |
| CVE-2020-1971 | MEDIUM | 5.9 | 7.0% | Dec 8, 2020 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known... |
| CVE-2020-29578 | CRITICAL | 9.8 | 2.2% | Dec 8, 2020 | The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems u... |
| CVE-2020-26255 | CRITICAL | 9.1 | 1.5% | Dec 8, 2020 | Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with... |
| CVE-2020-26254 | HIGH | 7.7 | 1.3% | Dec 8, 2020 | omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before vers... |
| CVE-2020-25955 | MEDIUM | 5.4 | 0.9% | Dec 8, 2020 | SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS)... |
| CVE-2020-29540 | HIGH | 7.5 | 1.2% | Dec 8, 2020 | API calls in the Translation API feature in Systran Pure Neural Server before 9.7.0 allow a threat actor to use the Syst... |
| CVE-2020-29539 | MEDIUM | 5.4 | 0.7% | Dec 8, 2020 | A Cross-Site Scripting (XSS) issue in WebUI Translation in Systran Pure Neural Server before 9.7.0 allows a threat actor... |
| CVE-2020-25889 | CRITICAL | 9.8 | 2.7% | Dec 8, 2020 | Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injec... |
| CVE-2020-17531 | CRITICAL | 9.8 | 9.7% | Dec 8, 2020 | A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp... |
| CVE-2020-26253 | MEDIUM | 5.9 | 0.6% | Dec 8, 2020 | Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulne... |
| CVE-2020-27822 | MEDIUM | 5.9 | 1.1% | Dec 8, 2020 | A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final.... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now