2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5933 | HIGH | 7.5 | 1.1% | Oct 29, 2020 | On versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, when a BIG-IP syste... |
| CVE-2020-5932 | MEDIUM | 4.8 | 0.5% | Oct 29, 2020 | On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility... |
| CVE-2020-5931 | HIGH | 7.5 | 1.0% | Oct 29, 2020 | On BIG-IP 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, Virtual servers with ... |
| CVE-2020-4864 | MEDIUM | 4.3 | 0.4% | Oct 29, 2020 | IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP... |
| CVE-2020-4724 | HIGH | 7.8 | 1.5% | Oct 29, 2020 | IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by ... |
| CVE-2020-4723 | HIGH | 7.8 | 1.5% | Oct 29, 2020 | IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by ... |
| CVE-2020-4722 | HIGH | 7.8 | 1.5% | Oct 29, 2020 | IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by ... |
| CVE-2020-4721 | HIGH | 7.8 | 1.5% | Oct 29, 2020 | IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by ... |
| CVE-2020-27993 | MEDIUM | 5.3 | 2.5% | Oct 29, 2020 | Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files. |
| CVE-2020-7384 | HIGH | 7.8 | 30.6% | Oct 29, 2020 | Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish ... |
| CVE-2020-5938 | MEDIUM | 6.5 | 0.5% | Oct 29, 2020 | On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authent... |
| CVE-2020-5937 | HIGH | 7.5 | 1.3% | Oct 29, 2020 | On BIG-IP AFM 15.1.0-15.1.0.5, the Traffic Management Microkernel (TMM) may produce a core file while processing layer 4... |
| CVE-2020-21266 | MEDIUM | 6.1 | 0.6% | Oct 29, 2020 | Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability. |
| CVE-2020-25516 | MEDIUM | 5.4 | 0.6% | Oct 29, 2020 | WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer ... |
| CVE-2020-27658 | MEDIUM | 6.1 | 1.3% | Oct 29, 2020 | Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the sessio... |
| CVE-2020-27657 | MEDIUM | 5.9 | 0.6% | Oct 29, 2020 | Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081... |
| CVE-2020-27656 | LOW | 3.7 | 0.5% | Oct 29, 2020 | Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3... |
| CVE-2020-27655 | CRITICAL | 10 | 1.7% | Oct 29, 2020 | Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to acce... |
| CVE-2020-27654 | CRITICAL | 9.8 | 4.6% | Oct 29, 2020 | Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers ... |
| CVE-2020-27653 | HIGH | 8.3 | 0.8% | Oct 29, 2020 | Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-m... |
| CVE-2020-27652 | HIGH | 8.3 | 0.8% | Oct 29, 2020 | Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-... |
| CVE-2020-27651 | HIGH | 8.1 | 0.8% | Oct 29, 2020 | Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session,... |
| CVE-2020-27650 | LOW | 3.7 | 0.6% | Oct 29, 2020 | Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS ... |
| CVE-2020-27649 | CRITICAL | 9 | 0.7% | Oct 29, 2020 | Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allow... |
| CVE-2020-27648 | CRITICAL | 9 | 0.7% | Oct 29, 2020 | Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now