2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14746 | MEDIUM | 4.7 | 1.2% | Oct 21, 2020 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popup windows). Suppor... |
| CVE-2020-14745 | MEDIUM | 4.3 | 0.9% | Oct 21, 2020 | Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General). Supported vers... |
| CVE-2020-14744 | MEDIUM | 6.5 | 1.3% | Oct 21, 2020 | Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General). Supported vers... |
| CVE-2020-14743 | LOW | 3.1 | 0.7% | Oct 21, 2020 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.... |
| CVE-2020-14742 | LOW | 2.7 | 0.9% | Oct 21, 2020 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, ... |
| CVE-2020-14741 | MEDIUM | 4.9 | 1.2% | Oct 21, 2020 | Vulnerability in the Database Filesystem component of Oracle Database Server. Supported versions that are affected are 1... |
| CVE-2020-14740 | LOW | 2.8 | 0.4% | Oct 21, 2020 | Vulnerability in the SQL Developer Install component of Oracle Database Server. Supported versions that are affected are... |
| CVE-2020-14736 | LOW | 3.8 | 0.8% | Oct 21, 2020 | Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 11.2.0... |
| CVE-2020-14735 | HIGH | 8.8 | 0.4% | Oct 21, 2020 | Vulnerability in the Scheduler component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 1... |
| CVE-2020-14734 | HIGH | 8.1 | 1.7% | Oct 21, 2020 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4,... |
| CVE-2020-14732 | LOW | 3.1 | 0.8% | Oct 21, 2020 | Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications... |
| CVE-2020-14731 | LOW | 3.1 | 0.8% | Oct 21, 2020 | Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications... |
| CVE-2020-14672 | MEDIUM | 4.9 | 2.4% | Oct 21, 2020 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that... |
| CVE-2020-6648 | MEDIUM | 6.5 | 0.6% | Oct 21, 2020 | A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earli... |
| CVE-2020-10140 | HIGH | 7.3 | 0.4% | Oct 21, 2020 | Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged proc... |
| CVE-2020-10139 | HIGH | 7.8 | 0.4% | Oct 21, 2020 | Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\... |
| CVE-2020-10138 | HIGH | 7.8 | 0.5% | Oct 21, 2020 | Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a s... |
| CVE-2020-25820 | MEDIUM | 6.5 | 8.8% | Oct 21, 2020 | BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploade... |
| CVE-2020-26896 | HIGH | 8.2 | 0.7% | Oct 21, 2020 | Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chai... |
| CVE-2020-26895 | MEDIUM | 5.3 | 0.7% | Oct 21, 2020 | Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast t... |
| CVE-2020-5792 | HIGH | 7.2 | 61.0% | Oct 20, 2020 | Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user... |
| CVE-2020-5791 | HIGH | 7.2 | 78.6% | Oct 20, 2020 | Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi... |
| CVE-2020-5790 | MEDIUM | 6.5 | 2.2% | Oct 20, 2020 | Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by trick... |
| CVE-2020-25648 | HIGH | 7.5 | 3.9% | Oct 20, 2020 | A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker t... |
| CVE-2020-25157 | HIGH | 7.5 | 1.4% | Oct 20, 2020 | The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now