2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14299 | MEDIUM | 6.5 | 1.4% | Oct 16, 2020 | A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegat... |
| CVE-2020-14144 | HIGH | 7.2 | 93.7% | Oct 16, 2020 | The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer envir... |
| CVE-2020-26893 | HIGH | 7.8 | 0.2% | Oct 16, 2020 | An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (runn... |
| CVE-2020-26943 | CRITICAL | 9.9 | 3.1% | Oct 16, 2020 | An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blaza... |
| CVE-2020-26584 | MEDIUM | 6.1 | 0.9% | Oct 16, 2020 | An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog... |
| CVE-2020-26583 | MEDIUM | 6.1 | 1.0% | Oct 16, 2020 | An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (... |
| CVE-2020-25829 | HIGH | 7.5 | 6.5% | Oct 16, 2020 | An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacke... |
| CVE-2020-24352 | MEDIUM | 5.5 | 0.4% | Oct 16, 2020 | An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementa... |
| CVE-2020-27176 | CRITICAL | 9.6 | 1.8% | Oct 16, 2020 | Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a du... |
| CVE-2020-27174 | HIGH | 7.5 | 1.7% | Oct 16, 2020 | In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage w... |
| CVE-2020-27173 | HIGH | 7.5 | 1.5% | Oct 16, 2020 | In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input so... |
| CVE-2020-27163 | MEDIUM | 6.1 | 0.7% | Oct 16, 2020 | phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter. |
| CVE-2020-14185 | MEDIUM | 5.3 | 1.9% | Oct 15, 2020 | Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permission... |
| CVE-2020-7591 | HIGH | 8.8 | 1.5% | Oct 15, 2020 | A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow a... |
| CVE-2020-1777 | MEDIUM | 5.3 | 0.8% | Oct 15, 2020 | Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as ... |
| CVE-2020-15794 | MEDIUM | 4.3 | 0.8% | Oct 15, 2020 | A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show th... |
| CVE-2020-15793 | MEDIUM | 5.4 | 0.7% | Oct 15, 2020 | A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Optio... |
| CVE-2020-15792 | MEDIUM | 4.3 | 1.0% | Oct 15, 2020 | A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input vali... |
| CVE-2020-12504 | CRITICAL | 9.8 | 3.0% | Oct 15, 2020 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv... |
| CVE-2020-12503 | HIGH | 7.2 | 23.3% | Oct 15, 2020 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv... |
| CVE-2020-12502 | HIGH | 8.8 | 1.0% | Oct 15, 2020 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv... |
| CVE-2020-12501 | CRITICAL | 9.8 | 3.3% | Oct 15, 2020 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv... |
| CVE-2020-12500 | CRITICAL | 9.8 | 2.9% | Oct 15, 2020 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv... |
| CVE-2020-25859 | MEDIUM | 6.7 | 0.3% | Oct 15, 2020 | The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() ca... |
| CVE-2020-25858 | HIGH | 7.5 | 9.6% | Oct 15, 2020 | The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not val... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now