2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15437 | MEDIUM | 4.4 | 0.4% | Nov 23, 2020 | The Linux kernel before version 5.8 is vulnerable to a NULL pointer dereference in drivers/tty/serial/8250/8250_core.c:s... |
| CVE-2020-15436 | MEDIUM | 6.7 | 0.9% | Nov 23, 2020 | Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or c... |
| CVE-2020-28927 | MEDIUM | 6.1 | 0.7% | Nov 23, 2020 | There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user secti... |
| CVE-2020-15249 | MEDIUM | 5.4 | 0.5% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version... |
| CVE-2020-15248 | MEDIUM | 4.2 | 0.3% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version... |
| CVE-2020-15247 | MEDIUM | 5.2 | 0.3% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version... |
| CVE-2020-15246 | HIGH | 7.5 | 1.7% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version... |
| CVE-2020-7927 | MEDIUM | 6.5 | 1.0% | Nov 23, 2020 | Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key ... |
| CVE-2020-28896 | MEDIUM | 5.3 | 2.3% | Nov 23, 2020 | Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's ini... |
| CVE-2020-28864 | CRITICAL | 9.8 | 2.8% | Nov 23, 2020 | Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspe... |
| CVE-2020-26239 | MEDIUM | 5.4 | 1.0% | Nov 23, 2020 | Scratch Addons is a WebExtension that supports both Chrome and Firefox. Scratch Addons before version 1.3.2 is vulnerabl... |
| CVE-2020-7928 | MEDIUM | 6.5 | 1.4% | Nov 23, 2020 | A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing speciall... |
| CVE-2020-6939 | CRITICAL | 9.8 | 1.8% | Nov 23, 2020 | Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users... |
| CVE-2020-4854 | CRITICAL | 9.8 | 2.4% | Nov 23, 2020 | IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key... |
| CVE-2020-4783 | MEDIUM | 5.9 | 1.2% | Nov 23, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by... |
| CVE-2020-4771 | MEDIUM | 5.3 | 1.5% | Nov 23, 2020 | IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attack... |
| CVE-2020-12352 | MEDIUM | 6.5 | 5.7% | Nov 23, 2020 | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja... |
| CVE-2020-12351 | HIGH | 8.8 | 7.7% | Nov 23, 2020 | Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a... |
| CVE-2020-0569 | MEDIUM | 5.7 | 0.6% | Nov 23, 2020 | Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potential... |
| CVE-2020-7777 | HIGH | 7.2 | 2.0% | Nov 23, 2020 | This affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript... |
| CVE-2020-28421 | HIGH | 7.8 | 0.3% | Nov 23, 2020 | CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that ... |
| CVE-2020-1778 | MEDIUM | 4.3 | 0.6% | Nov 23, 2020 | When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is se... |
| CVE-2020-7926 | MEDIUM | 6.5 | 1.4% | Nov 23, 2020 | A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which vio... |
| CVE-2020-7925 | HIGH | 7.5 | 1.7% | Nov 23, 2020 | Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthent... |
| CVE-2020-28053 | MEDIUM | 6.5 | 1.4% | Nov 23, 2020 | HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now