2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28373 | HIGH | 8.8 | 1.0% | Nov 9, 2020 | upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overfl... |
| CVE-2020-28371 | CRITICAL | 9.8 | 1.7% | Nov 9, 2020 | An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. The FileOutputStream.write() method in FileOutputStr... |
| CVE-2020-26168 | CRITICAL | 9.8 | 1.6% | Nov 9, 2020 | The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x ... |
| CVE-2020-14189 | CRITICAL | 9.8 | 2.3% | Nov 9, 2020 | The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to ex... |
| CVE-2020-14188 | CRITICAL | 9.8 | 2.8% | Nov 9, 2020 | The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to... |
| CVE-2020-4759 | HIGH | 7.8 | 2.0% | Nov 9, 2020 | IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute ... |
| CVE-2020-4651 | MEDIUM | 4.8 | 0.3% | Nov 9, 2020 | IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery w... |
| CVE-2020-4650 | LOW | 3.3 | 0.3% | Nov 9, 2020 | IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which c... |
| CVE-2020-28364 | MEDIUM | 6.1 | 0.6% | Nov 9, 2020 | A stored cross-site scripting (XSS) vulnerability affects the Web UI in Locust before 1.3.2, if the installation violate... |
| CVE-2020-27977 | HIGH | 7.8 | 0.3% | Nov 9, 2020 | CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts... |
| CVE-2020-26542 | CRITICAL | 9.8 | 1.5% | Nov 9, 2020 | An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDA... |
| CVE-2020-23140 | HIGH | 8.1 | 1.0% | Nov 9, 2020 | Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user... |
| CVE-2020-23139 | MEDIUM | 5.5 | 0.3% | Nov 9, 2020 | Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which ... |
| CVE-2020-23138 | CRITICAL | 9.8 | 1.3% | Nov 9, 2020 | An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can up... |
| CVE-2020-23136 | MEDIUM | 5.5 | 0.3% | Nov 9, 2020 | Microweber v1.1.18 is affected by no session expiry after log-out. |
| CVE-2020-14366 | HIGH | 7.5 | 1.4% | Nov 9, 2020 | A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible b... |
| CVE-2020-9300 | MEDIUM | 6.5 | 0.9% | Nov 9, 2020 | The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, ... |
| CVE-2020-9299 | MEDIUM | 5.4 | 0.6% | Nov 9, 2020 | There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description param... |
| CVE-2020-8276 | MEDIUM | 5.5 | 0.4% | Nov 9, 2020 | The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the times... |
| CVE-2020-8268 | HIGH | 7.5 | 1.3% | Nov 9, 2020 | Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify metho... |
| CVE-2020-8150 | MEDIUM | 4.1 | 0.3% | Nov 9, 2020 | A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the in... |
| CVE-2020-8133 | MEDIUM | 5.3 | 0.7% | Nov 9, 2020 | A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite... |
| CVE-2020-25655 | MEDIUM | 6.5 | 0.6% | Nov 9, 2020 | An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct... |
| CVE-2020-24353 | MEDIUM | 6.1 | 0.6% | Nov 9, 2020 | Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header. |
| CVE-2020-15297 | CRITICAL | 9.1 | 0.8% | Nov 9, 2020 | Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tool... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now