2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15668 | MEDIUM | 4.3 | 0.5% | Oct 1, 2020 | A lock was missing when accessing a data structure and importing certificate information into the trust database. This v... |
| CVE-2020-15667 | HIGH | 8.8 | 1.6% | Oct 1, 2020 | When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap... |
| CVE-2020-15666 | MEDIUM | 6.5 | 1.2% | Oct 1, 2020 | When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was... |
| CVE-2020-15665 | MEDIUM | 4.3 | 0.7% | Oct 1, 2020 | Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. T... |
| CVE-2020-15664 | MEDIUM | 6.5 | 1.4% | Oct 1, 2020 | By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access t... |
| CVE-2020-15663 | HIGH | 8.8 | 2.6% | Oct 1, 2020 | If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the... |
| CVE-2020-15533 | CRITICAL | 9.8 | 4.2% | Oct 1, 2020 | In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalati... |
| CVE-2020-15227 | CRITICAL | 9.8 | 35.2% | Oct 1, 2020 | Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passin... |
| CVE-2020-25200 | MEDIUM | 5.3 | 7.5% | Oct 1, 2020 | Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Ini... |
| CVE-2020-15228 | MEDIUM | 5 | 1.4% | Oct 1, 2020 | In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Act... |
| CVE-2020-25018 | HIGH | 7.5 | 1.1% | Oct 1, 2020 | Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization. |
| CVE-2020-25017 | HIGH | 8.3 | 1.3% | Oct 1, 2020 | Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy... |
| CVE-2020-24620 | HIGH | 7.8 | 0.3% | Oct 1, 2020 | Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager ... |
| CVE-2020-16844 | MEDIUM | 6.8 | 1.1% | Oct 1, 2020 | In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY ... |
| CVE-2020-4576 | HIGH | 7.5 | 2.0% | Oct 1, 2020 | IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive in... |
| CVE-2020-25990 | CRITICAL | 9.8 | 1.6% | Oct 1, 2020 | WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Explo... |
| CVE-2020-24861 | MEDIUM | 5.4 | 0.9% | Oct 1, 2020 | GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is execu... |
| CVE-2020-24860 | MEDIUM | 5.4 | 1.1% | Oct 1, 2020 | CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persisten... |
| CVE-2020-8109 | HIGH | 7.5 | 0.9% | Oct 1, 2020 | A vulnerability has been discovered in the ace.xmd parser that results from a lack of proper validation of user-supplied... |
| CVE-2020-6654 | HIGH | 7.8 | 0.4% | Sep 30, 2020 | A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attac... |
| CVE-2020-26159 | — | — | — | Sep 30, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Further investigation showed that it was not a secu... |
| CVE-2020-25830 | MEDIUM | 4.8 | 1.7% | Sep 30, 2020 | An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inje... |
| CVE-2020-25781 | MEDIUM | 4.3 | 0.9% | Sep 30, 2020 | An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes... |
| CVE-2020-25288 | MEDIUM | 4.8 | 1.5% | Sep 30, 2020 | An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafte... |
| CVE-2020-16234 | HIGH | 7.8 | 1.3% | Sep 30, 2020 | In PLC WinProladder Version 3.28 and prior, a stack-based buffer overflow vulnerability can be exploited when a valid us... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now