2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7746 | CRITICAL | 9.8 | 4.7% | Oct 29, 2020 | This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. Wh... |
| CVE-2020-11616 | HIGH | 7.5 | 1.3% | Oct 29, 2020 | NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which... |
| CVE-2020-11615 | HIGH | 7.5 | 1.2% | Oct 29, 2020 | NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which... |
| CVE-2020-11489 | HIGH | 7.5 | 1.3% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior... |
| CVE-2020-11488 | MEDIUM | 6.7 | 0.2% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior... |
| CVE-2020-11487 | HIGH | 7.5 | 1.3% | Oct 29, 2020 | NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06... |
| CVE-2020-11486 | CRITICAL | 9.8 | 2.6% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmwa... |
| CVE-2020-11485 | HIGH | 8.8 | 0.8% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) ... |
| CVE-2020-11484 | MEDIUM | 4.9 | 1.1% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmw... |
| CVE-2020-11483 | CRITICAL | 9.8 | 1.4% | Oct 29, 2020 | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior... |
| CVE-2020-27986 | HIGH | 7.5 | 16.2% | Oct 28, 2020 | SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settin... |
| CVE-2020-27981 | — | — | — | Oct 28, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-25374 | LOW | 2.6 | 0.6% | Oct 28, 2020 | CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error ... |
| CVE-2020-24713 | HIGH | 7.5 | 1.1% | Oct 28, 2020 | Gophish through 0.10.1 does not invalidate the gophish cookie upon logout. |
| CVE-2020-24712 | MEDIUM | 5.4 | 0.9% | Oct 28, 2020 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page. |
| CVE-2020-24711 | MEDIUM | 6.5 | 1.5% | Oct 28, 2020 | The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via... |
| CVE-2020-24710 | MEDIUM | 5.3 | 1.3% | Oct 28, 2020 | Gophish before 0.11.0 allows SSRF attacks. |
| CVE-2020-24709 | MEDIUM | 5.4 | 0.5% | Oct 28, 2020 | Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template. |
| CVE-2020-24708 | MEDIUM | 5.4 | 0.6% | Oct 28, 2020 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form. |
| CVE-2020-24707 | HIGH | 7.8 | 1.3% | Oct 28, 2020 | Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content. |
| CVE-2020-27980 | MEDIUM | 5.4 | 0.6% | Oct 28, 2020 | Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to... |
| CVE-2020-27742 | MEDIUM | 6.5 | 1.1% | Oct 28, 2020 | An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to... |
| CVE-2020-27741 | MEDIUM | 6.1 | 0.8% | Oct 28, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbit... |
| CVE-2020-27740 | MEDIUM | 5.3 | 1.3% | Oct 28, 2020 | Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. NOTE: t... |
| CVE-2020-27739 | CRITICAL | 9.8 | 1.8% | Oct 28, 2020 | A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now