2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3459 | HIGH | 7.8 | 0.4% | Oct 21, 2020 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary comma... |
| CVE-2020-3458 | MEDIUM | 6.7 | 0.3% | Oct 21, 2020 | Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Th... |
| CVE-2020-3457 | MEDIUM | 6.7 | 0.4% | Oct 21, 2020 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary comma... |
| CVE-2020-3456 | HIGH | 8.8 | 0.5% | Oct 21, 2020 | A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remo... |
| CVE-2020-3455 | HIGH | 7.8 | 0.3% | Oct 21, 2020 | A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass... |
| CVE-2020-3436 | HIGH | 8.6 | 1.9% | Oct 21, 2020 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defe... |
| CVE-2020-3410 | HIGH | 8.1 | 1.1% | Oct 21, 2020 | A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Softwa... |
| CVE-2020-3373 | HIGH | 8.6 | 1.9% | Oct 21, 2020 | A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco... |
| CVE-2020-3352 | MEDIUM | 5.5 | 0.3% | Oct 21, 2020 | A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker... |
| CVE-2020-3317 | HIGH | 7.5 | 1.0% | Oct 21, 2020 | A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthen... |
| CVE-2020-3304 | HIGH | 8.6 | 3.9% | Oct 21, 2020 | A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (F... |
| CVE-2020-3299 | MEDIUM | 5.8 | 2.3% | Oct 21, 2020 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticate... |
| CVE-2020-17381 | HIGH | 7.3 | 0.4% | Oct 21, 2020 | An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installa... |
| CVE-2020-15240 | CRITICAL | 9.1 | 0.8% | Oct 21, 2020 | omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_... |
| CVE-2020-7750 | CRITICAL | 9.6 | 6.1% | Oct 21, 2020 | This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not e... |
| CVE-2020-5651 | HIGH | 8.8 | 1.5% | Oct 21, 2020 | SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQ... |
| CVE-2020-5650 | MEDIUM | 6.1 | 0.9% | Oct 21, 2020 | Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arb... |
| CVE-2020-27613 | HIGH | 8.4 | 0.3% | Oct 21, 2020 | The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which al... |
| CVE-2020-27612 | MEDIUM | 4.3 | 0.7% | Oct 21, 2020 | Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information ... |
| CVE-2020-27611 | HIGH | 7.3 | 0.7% | Oct 21, 2020 | BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint. |
| CVE-2020-27610 | HIGH | 7.5 | 1.2% | Oct 21, 2020 | The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external inte... |
| CVE-2020-27609 | MEDIUM | 5.3 | 0.8% | Oct 21, 2020 | BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. ... |
| CVE-2020-27608 | MEDIUM | 6.1 | 0.7% | Oct 21, 2020 | In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, w... |
| CVE-2020-27607 | MEDIUM | 6.5 | 0.8% | Oct 21, 2020 | In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop acce... |
| CVE-2020-27606 | MEDIUM | 5.3 | 1.1% | Oct 21, 2020 | BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now