2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24416MEDIUM6.1Marketo Sales Insight plugin version 1.4355 (and earlier) is affected by a blind stored Cross-Site Scripting (XSS) vulne...
CVE-2020-24415HIGH7.8Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing...
CVE-2020-24414HIGH7.8Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing...
CVE-2020-24413HIGH7.8Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing...
CVE-2020-24412HIGH7.8Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing...
CVE-2020-24411HIGH7.8Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds write vulnerability when handling crafted P...
CVE-2020-24410HIGH7.8Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF...
CVE-2020-24409HIGH7.8Adobe Illustrator version 24.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing crafted PDF...
CVE-2020-9417HIGH8.8The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO...
CVE-2020-15269CRITICAL9.1In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoin...
CVE-2020-15264HIGH7.8The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH enviro...
CVE-2020-24765HIGH7.5InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a...
CVE-2020-15931HIGH7.5Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challeng...
CVE-2020-7371MEDIUM4.3User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser all...
CVE-2020-7370MEDIUM4.3User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bol...
CVE-2020-7369MEDIUM4.3User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser all...
CVE-2020-7364MEDIUM4.3User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser all...
CVE-2020-7363MEDIUM4.3User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser all...
CVE-2020-3995MEDIUM5.3In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fus...
CVE-2020-3994HIGH7.4VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Serve...
CVE-2020-3993MEDIUM5.9VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allo...
CVE-2020-3992CRITICAL9.8OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-...
CVE-2020-3982HIGH7.7VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Work...
CVE-2020-3981MEDIUM5.8VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Work...
CVE-2020-4756MEDIUM5.5IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now