2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4774 | MEDIUM | 5.4 | 0.8% | Oct 12, 2020 | An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling ... |
| CVE-2020-4773 | MEDIUM | 6.5 | 0.6% | Oct 12, 2020 | A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which... |
| CVE-2020-4772 | HIGH | 8.1 | 1.4% | Oct 12, 2020 | An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A ... |
| CVE-2020-4699 | MEDIUM | 5.3 | 0.4% | Oct 12, 2020 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin... |
| CVE-2020-4661 | MEDIUM | 5.3 | 0.4% | Oct 12, 2020 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin... |
| CVE-2020-4660 | MEDIUM | 5.3 | 0.4% | Oct 12, 2020 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive usin... |
| CVE-2020-5143 | MEDIUM | 5.3 | 1.6% | Oct 12, 2020 | SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username... |
| CVE-2020-5142 | MEDIUM | 6.1 | 1.1% | Oct 12, 2020 | A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated a... |
| CVE-2020-5141 | MEDIUM | 6.5 | 1.3% | Oct 12, 2020 | A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firew... |
| CVE-2020-5140 | HIGH | 7.5 | 1.7% | Oct 12, 2020 | A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSL... |
| CVE-2020-5139 | HIGH | 7.5 | 1.7% | Oct 12, 2020 | A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due ... |
| CVE-2020-5138 | HIGH | 7.5 | 1.7% | Oct 12, 2020 | A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) o... |
| CVE-2020-5137 | HIGH | 7.5 | 1.7% | Oct 12, 2020 | A buffer overflow vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on ... |
| CVE-2020-5136 | MEDIUM | 6.5 | 1.1% | Oct 12, 2020 | A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-... |
| CVE-2020-5135 | CRITICAL | 9.8 | 26.9% | Oct 12, 2020 | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially exe... |
| CVE-2020-5134 | MEDIUM | 6.5 | 1.1% | Oct 12, 2020 | A vulnerability in SonicOS allows an authenticated attacker to cause out-of-bound invalid file reference leads to a fire... |
| CVE-2020-5133 | HIGH | 7.5 | 1.7% | Oct 12, 2020 | A vulnerability in SonicOS allows a remote unauthenticated attacker to cause Denial of Service due to buffer overflow, w... |
| CVE-2020-14184 | MEDIUM | 5.4 | 0.9% | Oct 12, 2020 | Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Sit... |
| CVE-2020-26948 | CRITICAL | 9.8 | 87.2% | Oct 10, 2020 | Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter. |
| CVE-2020-26947 | HIGH | 7.8 | 0.4% | Oct 10, 2020 | monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead o... |
| CVE-2020-26945 | HIGH | 8.1 | 1.8% | Oct 10, 2020 | MyBatis before 3.5.6 mishandles deserialization of object streams. |
| CVE-2020-26935 | CRITICAL | 9.8 | 67.1% | Oct 10, 2020 | An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerabili... |
| CVE-2020-26934 | MEDIUM | 6.1 | 2.2% | Oct 10, 2020 | phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link. |
| CVE-2020-26932 | MEDIUM | 4.3 | 1.0% | Oct 10, 2020 | debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whe... |
| CVE-2020-9105 | MEDIUM | 6.7 | 0.2% | Oct 9, 2020 | Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now