2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26084 | MEDIUM | 6.5 | 0.9% | Nov 6, 2020 | A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files o... |
| CVE-2020-26083 | MEDIUM | 4.8 | 0.6% | Nov 6, 2020 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2020-26214 | CRITICAL | 9.8 | 65.9% | Nov 6, 2020 | In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when A... |
| CVE-2020-8577 | MEDIUM | 5.9 | 1.0% | Nov 6, 2020 | SANtricity OS Controller Software versions 11.50.1 and higher are susceptible to a vulnerability which could allow an at... |
| CVE-2020-5794 | HIGH | 7.8 | 0.4% | Nov 6, 2020 | A vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated l... |
| CVE-2020-26213 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | In teler before version 0.0.1, if you run teler inside a Docker container and encounter `errors.Exit` function, it will ... |
| CVE-2020-25174 | HIGH | 7.8 | 0.4% | Nov 6, 2020 | A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute c... |
| CVE-2020-25172 | CRITICAL | 9.8 | 2.0% | Nov 6, 2020 | A relative path traversal attack in the B. Braun OnlineSuite Version AP 3.0 and earlier allows unauthenticated attackers... |
| CVE-2020-25170 | HIGH | 7.8 | 1.0% | Nov 6, 2020 | An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earli... |
| CVE-2020-8580 | HIGH | 7.5 | 1.3% | Nov 6, 2020 | SANtricity OS Controller Software versions 11.30 and higher are susceptible to a vulnerability which allows an unauthent... |
| CVE-2020-7198 | HIGH | 8.8 | 2.0% | Nov 6, 2020 | There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synerg... |
| CVE-2020-5795 | MEDIUM | 6.2 | 1.0% | Nov 6, 2020 | UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physi... |
| CVE-2020-4484 | MEDIUM | 4.3 | 0.8% | Nov 6, 2020 | IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could disclose sensitive information to an authenticat... |
| CVE-2020-4483 | MEDIUM | 4.3 | 1.0% | Nov 6, 2020 | IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive info... |
| CVE-2020-4482 | MEDIUM | 6.5 | 0.9% | Nov 6, 2020 | IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security. ... |
| CVE-2020-27589 | HIGH | 7.5 | 1.1% | Nov 6, 2020 | Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certa... |
| CVE-2020-27196 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly par... |
| CVE-2020-26883 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of craf... |
| CVE-2020-26882 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON... |
| CVE-2020-10292 | HIGH | 8.2 | 1.5% | Nov 6, 2020 | Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove ... |
| CVE-2020-10291 | HIGH | 7.5 | 1.4% | Nov 6, 2020 | Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove ... |
| CVE-2020-28196 | HIGH | 7.5 | 4.4% | Nov 6, 2020 | MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerbero... |
| CVE-2020-27617 | MEDIUM | 6.5 | 2.5% | Nov 6, 2020 | eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the... |
| CVE-2020-27616 | MEDIUM | 6.5 | 2.5% | Nov 6, 2020 | ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can ... |
| CVE-2020-27152 | MEDIUM | 5.5 | 0.6% | Nov 6, 2020 | An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an i... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now