2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26519 | MEDIUM | 5.5 | 1.0% | Oct 2, 2020 | Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a de... |
| CVE-2020-26518 | CRITICAL | 9.8 | 2.0% | Oct 2, 2020 | Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/... |
| CVE-2020-26511 | HIGH | 7.5 | 2.1% | Oct 2, 2020 | The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This lead... |
| CVE-2020-9491 | HIGH | 7.5 | 2.8% | Oct 1, 2020 | In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connectio... |
| CVE-2020-9487 | HIGH | 7.5 | 3.0% | Oct 1, 2020 | In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did no... |
| CVE-2020-9486 | HIGH | 7.5 | 3.4% | Oct 1, 2020 | In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive proper... |
| CVE-2020-5789 | MEDIUM | 6.5 | 1.3% | Oct 1, 2020 | Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the cont... |
| CVE-2020-5788 | MEDIUM | 6.5 | 1.2% | Oct 1, 2020 | Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitr... |
| CVE-2020-5787 | MEDIUM | 6.5 | 1.6% | Oct 1, 2020 | Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitr... |
| CVE-2020-5786 | HIGH | 8.8 | 8.8% | Oct 1, 2020 | Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive applica... |
| CVE-2020-5785 | MEDIUM | 6.1 | 0.7% | Oct 1, 2020 | Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct r... |
| CVE-2020-5784 | MEDIUM | 6.5 | 0.7% | Oct 1, 2020 | Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the applicatio... |
| CVE-2020-5387 | MEDIUM | 4.4 | 0.3% | Oct 1, 2020 | Dell XPS 13 9370 BIOS versions prior to 1.13.1 contains an Improper Exception Handling vulnerability. A local attacker w... |
| CVE-2020-14223 | MEDIUM | 6.1 | 0.6% | Oct 1, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed i... |
| CVE-2020-13940 | MEDIUM | 5.5 | 1.9% | Oct 1, 2020 | In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider o... |
| CVE-2020-11979 | HIGH | 7.5 | 8.1% | Oct 1, 2020 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the... |
| CVE-2020-15678 | HIGH | 8.8 | 1.9% | Oct 1, 2020 | When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential u... |
| CVE-2020-15677 | MEDIUM | 6.1 | 1.6% | Oct 1, 2020 | By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the down... |
| CVE-2020-15676 | MEDIUM | 6.1 | 1.6% | Oct 1, 2020 | Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScr... |
| CVE-2020-15675 | HIGH | 8.8 | 1.0% | Oct 1, 2020 | When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially ex... |
| CVE-2020-15674 | HIGH | 8.8 | 0.8% | Oct 1, 2020 | Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corru... |
| CVE-2020-15673 | HIGH | 8.8 | 1.9% | Oct 1, 2020 | Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evi... |
| CVE-2020-15671 | LOW | 3.1 | 0.5% | Oct 1, 2020 | When typing in a password under certain conditions, a race may have occured where the InputContext was not being correct... |
| CVE-2020-15670 | HIGH | 8.8 | 1.1% | Oct 1, 2020 | Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of ... |
| CVE-2020-15669 | HIGH | 8.8 | 1.1% | Oct 1, 2020 | When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. T... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now