2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9857 | MEDIUM | 4.3 | 0.8% | Oct 27, 2020 | An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in... |
| CVE-2020-9786 | LOW | 3.3 | 0.6% | Oct 27, 2020 | This issue was addressed with improved checks This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mo... |
| CVE-2020-9782 | HIGH | 7.5 | 1.2% | Oct 27, 2020 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2020-9774 | HIGH | 7.5 | 0.6% | Oct 27, 2020 | An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting access to encrypted dat... |
| CVE-2020-3880 | HIGH | 7.8 | 1.3% | Oct 27, 2020 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and... |
| CVE-2020-3864 | HIGH | 7.8 | 0.4% | Oct 27, 2020 | A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for... |
| CVE-2020-3863 | HIGH | 7.8 | 1.3% | Oct 27, 2020 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3, Se... |
| CVE-2020-3855 | HIGH | 7.1 | 0.7% | Oct 27, 2020 | An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.3, Security... |
| CVE-2020-3852 | MEDIUM | 5.3 | 1.0% | Oct 27, 2020 | A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrec... |
| CVE-2020-3851 | HIGH | 7.8 | 0.8% | Oct 27, 2020 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Sec... |
| CVE-2020-27892 | HIGH | 7.5 | 1.4% | Oct 27, 2020 | The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZC... |
| CVE-2020-27891 | HIGH | 7.5 | 1.4% | Oct 27, 2020 | The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZC... |
| CVE-2020-27890 | HIGH | 8.2 | 1.0% | Oct 27, 2020 | The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZC... |
| CVE-2020-27888 | HIGH | 7.5 | 1.0% | Oct 27, 2020 | An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices... |
| CVE-2020-27160 | CRITICAL | 9.8 | 4.7% | Oct 27, 2020 | Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digi... |
| CVE-2020-27159 | CRITICAL | 9.8 | 5.9% | Oct 27, 2020 | Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validat... |
| CVE-2020-27158 | CRITICAL | 9.8 | 7.2% | Oct 27, 2020 | Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My... |
| CVE-2020-25765 | CRITICAL | 9.8 | 5.8% | Oct 27, 2020 | Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western ... |
| CVE-2020-12830 | CRITICAL | 9.8 | 3.2% | Oct 27, 2020 | Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privile... |
| CVE-2020-15238 | HIGH | 7 | 4.5% | Oct 27, 2020 | Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-me... |
| CVE-2020-7755 | HIGH | 7.5 | 2.1% | Oct 27, 2020 | All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted ... |
| CVE-2020-27853 | CRITICAL | 9.8 | 3.8% | Oct 27, 2020 | Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbi... |
| CVE-2020-26156 | — | — | — | Oct 27, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-11858 | HIGH | 7.8 | 2.7% | Oct 27, 2020 | Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Br... |
| CVE-2020-11854 | CRITICAL | 9.8 | 74.2% | Oct 27, 2020 | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bri... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now