2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9049 | MEDIUM | 5.3 | 0.5% | Nov 19, 2020 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could ... |
| CVE-2020-4718 | MEDIUM | 5.4 | 0.6% | Nov 19, 2020 | IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerabili... |
| CVE-2020-4701 | HIGH | 7.8 | 0.5% | Nov 19, 2020 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflo... |
| CVE-2020-28054 | HIGH | 7.5 | 2.0% | Nov 19, 2020 | JamoDat TSMManager Collector version up to 6.5.0.21 is vulnerable to an Authorization Bypass because the Collector compo... |
| CVE-2020-11831 | CRITICAL | 9.8 | 1.4% | Nov 19, 2020 | OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovo... |
| CVE-2020-11830 | CRITICAL | 9.8 | 1.4% | Nov 19, 2020 | QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.... |
| CVE-2020-11829 | CRITICAL | 9.8 | 1.1% | Nov 19, 2020 | Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.... |
| CVE-2020-15710 | MEDIUM | 6.1 | 0.3% | Nov 19, 2020 | Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. ... |
| CVE-2020-8279 | HIGH | 7.4 | 0.6% | Nov 19, 2020 | Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-mid... |
| CVE-2020-8278 | MEDIUM | 5.3 | 1.0% | Nov 19, 2020 | Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user. |
| CVE-2020-8277 | HIGH | 7.5 | 54.2% | Nov 19, 2020 | A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial... |
| CVE-2020-5947 | MEDIUM | 4.3 | 0.7% | Nov 19, 2020 | In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequenc... |
| CVE-2020-13360 | — | — | — | Nov 19, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-13359 | HIGH | 7.6 | 0.8% | Nov 19, 2020 | The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malici... |
| CVE-2020-13356 | HIGH | 8.2 | 1.8% | Nov 19, 2020 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request cou... |
| CVE-2020-13355 | HIGH | 8.1 | 1.7% | Nov 19, 2020 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS... |
| CVE-2020-12593 | HIGH | 7.5 | 2.0% | Nov 18, 2020 | Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a ... |
| CVE-2020-26226 | HIGH | 8.1 | 1.4% | Nov 18, 2020 | In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` c... |
| CVE-2020-26215 | MEDIUM | 6.1 | 1.2% | Nov 18, 2020 | Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook serve... |
| CVE-2020-22723 | MEDIUM | 6.1 | 0.8% | Nov 18, 2020 | A cross-site scripting (XSS) vulnerability in Beijing Liangjing Zhicheng Technology Co., Ltd ljcmsshop version 1.14 allo... |
| CVE-2020-15300 | MEDIUM | 6.1 | 0.7% | Nov 18, 2020 | SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document. |
| CVE-2020-14208 | MEDIUM | 5.4 | 0.6% | Nov 18, 2020 | SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerabi... |
| CVE-2020-13799 | MEDIUM | 6.8 | 0.3% | Nov 18, 2020 | Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specifie... |
| CVE-2020-25454 | MEDIUM | 5.4 | 0.7% | Nov 18, 2020 | Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the... |
| CVE-2020-15301 | HIGH | 7.8 | 0.8% | Nov 18, 2020 | SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Lead... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now