2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3998 | MEDIUM | 6.5 | 1.3% | Oct 23, 2020 | VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious att... |
| CVE-2020-3997 | MEDIUM | 5.4 | 0.7% | Oct 23, 2020 | VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful ex... |
| CVE-2020-27216 | HIGH | 7 | 4.3% | Oct 23, 2020 | In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta... |
| CVE-2020-26561 | HIGH | 8.8 | 12.2% | Oct 23, 2020 | Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprin... |
| CVE-2020-9361 | MEDIUM | 5.5 | 0.4% | Oct 23, 2020 | CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause... |
| CVE-2020-9331 | HIGH | 7.8 | 0.4% | Oct 23, 2020 | CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChang... |
| CVE-2020-26887 | HIGH | 7.8 | 1.4% | Oct 23, 2020 | FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism. |
| CVE-2020-15004 | MEDIUM | 4.8 | 2.8% | Oct 23, 2020 | OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS. |
| CVE-2020-15003 | MEDIUM | 4.3 | 0.8% | Oct 23, 2020 | OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string o... |
| CVE-2020-15002 | MEDIUM | 5 | 1.6% | Oct 23, 2020 | OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API. |
| CVE-2020-15270 | MEDIUM | 4.3 | 1.2% | Oct 22, 2020 | Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid.... |
| CVE-2020-3996 | MEDIUM | 5.5 | 0.3% | Oct 22, 2020 | Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in infor... |
| CVE-2020-27675 | MEDIUM | 4.7 | 0.3% | Oct 22, 2020 | An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_ba... |
| CVE-2020-27674 | MEDIUM | 5.3 | 0.4% | Oct 22, 2020 | An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying ke... |
| CVE-2020-27673 | MEDIUM | 5.5 | 0.4% | Oct 22, 2020 | An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a d... |
| CVE-2020-27672 | HIGH | 7 | 0.3% | Oct 22, 2020 | An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve ... |
| CVE-2020-27671 | HIGH | 7.8 | 0.3% | Oct 22, 2020 | An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data... |
| CVE-2020-27670 | HIGH | 7.8 | 0.3% | Oct 22, 2020 | An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption)... |
| CVE-2020-25186 | HIGH | 7.5 | 1.1% | Oct 22, 2020 | An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, wh... |
| CVE-2020-18129 | HIGH | 8.8 | 0.6% | Oct 22, 2020 | A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php. |
| CVE-2020-15684 | CRITICAL | 9.8 | 1.3% | Oct 22, 2020 | Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corru... |
| CVE-2020-15683 | CRITICAL | 9.8 | 2.6% | Oct 22, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of... |
| CVE-2020-15682 | MEDIUM | 6.5 | 0.5% | Oct 22, 2020 | When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application... |
| CVE-2020-15681 | HIGH | 7.5 | 1.1% | Oct 22, 2020 | When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could ha... |
| CVE-2020-15680 | MEDIUM | 5.3 | 0.9% | Oct 22, 2020 | If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguis... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now