2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29239 | MEDIUM | 6.1 | 0.5% | Dec 2, 2020 | Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result i... |
| CVE-2020-25266 | MEDIUM | 5.5 | 0.3% | Dec 2, 2020 | AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it w... |
| CVE-2020-25265 | MEDIUM | 6.5 | 1.9% | Dec 2, 2020 | AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by provid... |
| CVE-2020-13956 | MEDIUM | 5.3 | 8.7% | Dec 2, 2020 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request U... |
| CVE-2020-28273 | CRITICAL | 9.8 | 3.9% | Dec 2, 2020 | Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service ... |
| CVE-2020-28272 | CRITICAL | 9.8 | 3.3% | Dec 2, 2020 | Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service ... |
| CVE-2020-25638 | HIGH | 7.4 | 2.9% | Dec 2, 2020 | A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementatio... |
| CVE-2020-14369 | MEDIUM | 6.3 | 0.3% | Dec 2, 2020 | This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to ... |
| CVE-2020-12524 | HIGH | 7.5 | 1.1% | Dec 2, 2020 | Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W ... |
| CVE-2020-29458 | HIGH | 8.8 | 0.7% | Dec 2, 2020 | Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem. |
| CVE-2020-29456 | MEDIUM | 6.1 | 1.5% | Dec 2, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrar... |
| CVE-2020-5423 | HIGH | 7.5 | 1.1% | Dec 2, 2020 | CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticat... |
| CVE-2020-29454 | MEDIUM | 4.3 | 0.9% | Dec 2, 2020 | Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Ap... |
| CVE-2020-7199 | CRITICAL | 9.8 | 9.2% | Dec 2, 2020 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr... |
| CVE-2020-6018 | CRITICAL | 9.8 | 3.1% | Dec 2, 2020 | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_D... |
| CVE-2020-4102 | MEDIUM | 6.7 | 0.3% | Dec 2, 2020 | HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successfu... |
| CVE-2020-27816 | MEDIUM | 6.1 | 0.6% | Dec 2, 2020 | The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it i... |
| CVE-2020-27813 | HIGH | 7.5 | 2.3% | Dec 2, 2020 | An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An att... |
| CVE-2020-25723 | LOW | 3.2 | 0.4% | Dec 2, 2020 | A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB reques... |
| CVE-2020-25704 | MEDIUM | 5.5 | 0.3% | Dec 2, 2020 | A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET... |
| CVE-2020-25656 | MEDIUM | 4.1 | 0.4% | Dec 2, 2020 | A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKB... |
| CVE-2020-14383 | MEDIUM | 6.5 | 2.2% | Dec 2, 2020 | A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC s... |
| CVE-2020-14305 | HIGH | 8.1 | 5.1% | Dec 2, 2020 | An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functiona... |
| CVE-2020-14260 | CRITICAL | 9.8 | 1.4% | Dec 2, 2020 | HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successf... |
| CVE-2020-26250 | MEDIUM | 6.3 | 1.1% | Dec 1, 2020 | OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now