2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2048 | LOW | 3.3 | 0.3% | Nov 12, 2020 | An information exposure through log file vulnerability exists where the password for the configured system proxy server ... |
| CVE-2020-2022 | HIGH | 7.5 | 1.2% | Nov 12, 2020 | An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Pa... |
| CVE-2020-2000 | HIGH | 7.2 | 3.2% | Nov 12, 2020 | An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authentic... |
| CVE-2020-1999 | MEDIUM | 5.3 | 1.3% | Nov 12, 2020 | A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker t... |
| CVE-2020-5992 | HIGH | 7.8 | 0.5% | Nov 11, 2020 | NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its op... |
| CVE-2020-26221 | MEDIUM | 6.1 | 0.6% | Nov 11, 2020 | touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to sen... |
| CVE-2020-26220 | LOW | 3.5 | 0.7% | Nov 11, 2020 | toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploa... |
| CVE-2020-26219 | MEDIUM | 6.1 | 0.6% | Nov 11, 2020 | touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information ... |
| CVE-2020-26218 | MEDIUM | 6.1 | 1.9% | Nov 11, 2020 | touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting. The vulnerability allows an attacker to inject HT... |
| CVE-2020-8354 | MEDIUM | 6.7 | 0.2% | Nov 11, 2020 | A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook mod... |
| CVE-2020-8353 | MEDIUM | 6.7 | 0.5% | Nov 11, 2020 | Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configur... |
| CVE-2020-8352 | LOW | 2.4 | 0.3% | Nov 11, 2020 | In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration chang... |
| CVE-2020-5426 | CRITICAL | 9.8 | 0.7% | Nov 11, 2020 | Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a ... |
| CVE-2020-15275 | MEDIUM | 5.4 | 1.7% | Nov 11, 2020 | MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file ... |
| CVE-2020-27524 | HIGH | 7.1 | 1.2% | Nov 11, 2020 | On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %... |
| CVE-2020-27523 | HIGH | 7.5 | 2.0% | Nov 11, 2020 | Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, disp... |
| CVE-2020-4685 | HIGH | 7.2 | 1.4% | Nov 11, 2020 | A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to th... |
| CVE-2020-7768 | CRITICAL | 9.8 | 3.6% | Nov 11, 2020 | The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPac... |
| CVE-2020-7767 | MEDIUM | 5.3 | 1.6% | Nov 11, 2020 | All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validatin... |
| CVE-2020-7329 | HIGH | 7.2 | 1.6% | Nov 11, 2020 | Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote a... |
| CVE-2020-7328 | HIGH | 7.2 | 2.1% | Nov 11, 2020 | External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attack... |
| CVE-2020-1599 | MEDIUM | 5.5 | 19.1% | Nov 11, 2020 | Windows Spoofing Vulnerability |
| CVE-2020-1325 | MEDIUM | 5.4 | 1.5% | Nov 11, 2020 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability |
| CVE-2020-17113 | MEDIUM | 5.5 | 1.5% | Nov 11, 2020 | Windows Camera Codec Information Disclosure Vulnerability |
| CVE-2020-17110 | HIGH | 7.8 | 3.7% | Nov 11, 2020 | HEVC Video Extensions Remote Code Execution Vulnerability |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now