2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2048LOW3.3An information exposure through log file vulnerability exists where the password for the configured system proxy server ...
CVE-2020-2022HIGH7.5An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Pa...
CVE-2020-2000HIGH7.2An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authentic...
CVE-2020-1999MEDIUM5.3A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker t...
CVE-2020-5992HIGH7.8NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its op...
CVE-2020-26221MEDIUM6.1touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to sen...
CVE-2020-26220LOW3.5toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploa...
CVE-2020-26219MEDIUM6.1touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information ...
CVE-2020-26218MEDIUM6.1touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting. The vulnerability allows an attacker to inject HT...
CVE-2020-8354MEDIUM6.7A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook mod...
CVE-2020-8353MEDIUM6.7Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configur...
CVE-2020-8352LOW2.4In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration chang...
CVE-2020-5426CRITICAL9.8Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a ...
CVE-2020-15275MEDIUM5.4MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file ...
CVE-2020-27524HIGH7.1On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %...
CVE-2020-27523HIGH7.5Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, disp...
CVE-2020-4685HIGH7.2A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to th...
CVE-2020-7768CRITICAL9.8The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPac...
CVE-2020-7767MEDIUM5.3All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validatin...
CVE-2020-7329HIGH7.2Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote a...
CVE-2020-7328HIGH7.2External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attack...
CVE-2020-1599MEDIUM5.5Windows Spoofing Vulnerability
CVE-2020-1325MEDIUM5.4Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
CVE-2020-17113MEDIUM5.5Windows Camera Codec Information Disclosure Vulnerability
CVE-2020-17110HIGH7.8HEVC Video Extensions Remote Code Execution Vulnerability

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now