2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27621 | MEDIUM | 4.3 | 0.7% | Oct 22, 2020 | The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific u... |
| CVE-2020-27620 | MEDIUM | 6.1 | 0.9% | Oct 22, 2020 | The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. ... |
| CVE-2020-27619 | CRITICAL | 9.8 | 8.2% | Oct 22, 2020 | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via H... |
| CVE-2020-24421 | MEDIUM | 5.5 | 1.8% | Oct 21, 2020 | Adobe InDesign version 15.1.2 (and earlier) is affected by a NULL pointer dereference bug that occurs when handling a ma... |
| CVE-2020-17454 | MEDIUM | 6.1 | 0.8% | Oct 21, 2020 | WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it ... |
| CVE-2020-17355 | HIGH | 7.5 | 1.2% | Oct 21, 2020 | Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attack... |
| CVE-2020-27615 | CRITICAL | 9.8 | 53.6% | Oct 21, 2020 | The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa... |
| CVE-2020-24425 | HIGH | 7.8 | 0.7% | Oct 21, 2020 | Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead ... |
| CVE-2020-24424 | HIGH | 7.8 | 1.1% | Oct 21, 2020 | Adobe Premiere Pro version 14.4 (and earlier) is affected by an uncontrolled search path element that could result in ar... |
| CVE-2020-24423 | HIGH | 7.8 | 1.1% | Oct 21, 2020 | Adobe Media Encoder version 14.4 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that... |
| CVE-2020-24420 | HIGH | 7.8 | 0.8% | Oct 21, 2020 | Adobe Photoshop for Windows version 21.2.1 (and earlier) is affected by an uncontrolled search path element vulnerabilit... |
| CVE-2020-24419 | HIGH | 7.8 | 0.7% | Oct 21, 2020 | Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability th... |
| CVE-2020-24418 | HIGH | 7.8 | 3.0% | Oct 21, 2020 | Adobe After Effects version 17.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a craft... |
| CVE-2020-15266 | HIGH | 7.5 | 0.9% | Oct 21, 2020 | In Tensorflow before version 2.4.0, when the `boxes` argument of `tf.image.crop_and_resize` has a very large value, the ... |
| CVE-2020-15265 | HIGH | 7.5 | 0.9% | Oct 21, 2020 | In Tensorflow before version 2.4.0, an attacker can pass an invalid `axis` value to `tf.quantization.quantize_and_dequan... |
| CVE-2020-9750 | HIGH | 7.8 | 4.0% | Oct 21, 2020 | Adobe Animate version 20.5 (and earlier) is affected by an out-of-bounds read vulnerability, which could result in arbit... |
| CVE-2020-9749 | HIGH | 7.8 | 4.0% | Oct 21, 2020 | Adobe Animate version 20.5 (and earlier) is affected by an out-of-bounds read vulnerability that could result in arbitra... |
| CVE-2020-9748 | HIGH | 7.8 | 6.0% | Oct 21, 2020 | Adobe Animate version 20.5 (and earlier) is affected by a stack overflow vulnerability, which could lead to arbitrary co... |
| CVE-2020-9747 | HIGH | 7.8 | 4.0% | Oct 21, 2020 | Adobe Animate version 20.5 (and earlier) is affected by a double free vulnerability when parsing a crafted .fla file, wh... |
| CVE-2020-27344 | MEDIUM | 6.1 | 1.0% | Oct 21, 2020 | The cm-download-manager plugin before 2.8.0 for WordPress allows XSS. |
| CVE-2020-24422 | HIGH | 7.8 | 3.0% | Oct 21, 2020 | Adobe Creative Cloud Desktop Application version 5.2 (and earlier) and 2.1 (and earlier) for Windows is affected by an u... |
| CVE-2020-15244 | HIGH | 7.2 | 1.2% | Oct 21, 2020 | In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap cr... |
| CVE-2020-3599 | MEDIUM | 6.1 | 0.8% | Oct 21, 2020 | A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an... |
| CVE-2020-3585 | LOW | 3.7 | 1.3% | Oct 21, 2020 | A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defens... |
| CVE-2020-3583 | MEDIUM | 6.1 | 1.1% | Oct 21, 2020 | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now