2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9863 | HIGH | 7.8 | 1.3% | Oct 22, 2020 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13... |
| CVE-2020-9854 | HIGH | 7.8 | 0.4% | Oct 22, 2020 | A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10... |
| CVE-2020-9853 | HIGH | 7.8 | 0.8% | Oct 22, 2020 | A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malic... |
| CVE-2020-9828 | HIGH | 7.5 | 1.2% | Oct 22, 2020 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A rem... |
| CVE-2020-9810 | MEDIUM | 6.8 | 0.3% | Oct 22, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A person with phy... |
| CVE-2020-9796 | HIGH | 7 | 0.2% | Oct 22, 2020 | A race condition was addressed with improved state handling. This issue is fixed in macOS Catalina 10.15.5. An applicati... |
| CVE-2020-9787 | MEDIUM | 5.3 | 1.3% | Oct 22, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina ... |
| CVE-2020-9779 | HIGH | 7.1 | 0.3% | Oct 22, 2020 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A loc... |
| CVE-2020-9772 | MEDIUM | 5.5 | 0.3% | Oct 22, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina ... |
| CVE-2020-9771 | HIGH | 7.1 | 0.3% | Oct 22, 2020 | This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access t... |
| CVE-2020-3918 | MEDIUM | 5.5 | 0.3% | Oct 22, 2020 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, mac... |
| CVE-2020-3915 | HIGH | 7.8 | 0.3% | Oct 22, 2020 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malicious... |
| CVE-2020-3898 | HIGH | 7.8 | 0.4% | Oct 22, 2020 | A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An appl... |
| CVE-2020-15906 | CRITICAL | 9.8 | 27.4% | Oct 22, 2020 | tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. |
| CVE-2020-7020 | LOW | 3.1 | 1.0% | Oct 22, 2020 | Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security ... |
| CVE-2020-27195 | CRITICAL | 9.1 | 1.5% | Oct 22, 2020 | HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using eithe... |
| CVE-2020-27155 | HIGH | 7.5 | 1.3% | Oct 22, 2020 | An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted te... |
| CVE-2020-27533 | MEDIUM | 5.4 | 3.5% | Oct 22, 2020 | A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to ... |
| CVE-2020-26650 | MEDIUM | 5.3 | 1.0% | Oct 22, 2020 | AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php |
| CVE-2020-26649 | HIGH | 8.1 | 0.7% | Oct 22, 2020 | AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php |
| CVE-2020-27646 | MEDIUM | 6.5 | 1.0% | Oct 22, 2020 | Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft. |
| CVE-2020-27560 | LOW | 3.3 | 1.5% | Oct 22, 2020 | ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of ... |
| CVE-2020-24033 | HIGH | 8.8 | 1.0% | Oct 22, 2020 | An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authe... |
| CVE-2020-27642 | MEDIUM | 6.1 | 0.7% | Oct 22, 2020 | A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Gre... |
| CVE-2020-27638 | HIGH | 7.5 | 2.3% | Oct 22, 2020 | receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type c... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now