2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24426 | LOW | 3.3 | 3.0% | Nov 5, 2020 | Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) a... |
| CVE-2020-8267 | MEDIUM | 5.3 | 1.2% | Nov 5, 2020 | A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect cont... |
| CVE-2020-13661 | HIGH | 8.8 | 1.1% | Nov 5, 2020 | Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing sp... |
| CVE-2020-12147 | HIGH | 8.8 | 1.5% | Nov 5, 2020 | In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unautho... |
| CVE-2020-12146 | HIGH | 8.8 | 27.6% | Nov 5, 2020 | In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modi... |
| CVE-2020-12145 | CRITICAL | 9.8 | 6.0% | Nov 5, 2020 | Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API... |
| CVE-2020-26507 | HIGH | 7.8 | 1.0% | Nov 5, 2020 | A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 al... |
| CVE-2020-4097 | MEDIUM | 6.8 | 0.3% | Nov 5, 2020 | In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack... |
| CVE-2020-26505 | MEDIUM | 6.1 | 0.7% | Nov 5, 2020 | A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an atta... |
| CVE-2020-14240 | MEDIUM | 6.1 | 0.7% | Nov 5, 2020 | HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site ... |
| CVE-2020-14222 | MEDIUM | 6.1 | 0.6% | Nov 5, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to ref... |
| CVE-2020-26506 | MEDIUM | 4.3 | 0.8% | Nov 5, 2020 | An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower priv... |
| CVE-2020-25399 | HIGH | 7.8 | 1.0% | Nov 5, 2020 | Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malic... |
| CVE-2020-25398 | HIGH | 8.8 | 2.0% | Nov 5, 2020 | CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality. |
| CVE-2020-28115 | HIGH | 8.8 | 0.9% | Nov 5, 2020 | SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arb... |
| CVE-2020-28047 | MEDIUM | 5.4 | 0.8% | Nov 5, 2020 | AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration... |
| CVE-2020-27955 | CRITICAL | 9.8 | 82.7% | Nov 5, 2020 | Git LFS 2.12.0 allows Remote Code Execution. |
| CVE-2020-27688 | HIGH | 7.5 | 1.9% | Nov 5, 2020 | RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. ... |
| CVE-2020-27402 | HIGH | 7.8 | 0.5% | Nov 5, 2020 | The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /... |
| CVE-2020-24849 | HIGH | 8.8 | 3.2% | Nov 5, 2020 | A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metachara... |
| CVE-2020-15952 | CRITICAL | 9 | 1.5% | Nov 5, 2020 | Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permi... |
| CVE-2020-15951 | MEDIUM | 6.1 | 1.0% | Nov 5, 2020 | Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject ar... |
| CVE-2020-15950 | HIGH | 8.8 | 1.3% | Nov 5, 2020 | Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout. |
| CVE-2020-15949 | HIGH | 7.5 | 1.3% | Nov 5, 2020 | Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover. |
| CVE-2020-7763 | HIGH | 7.5 | 1.6% | Nov 5, 2020 | This affects the package phantom-html-to-pdf before 0.6.1. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now