2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4620 | HIGH | 8.8 | 5.2% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the ... |
| CVE-2020-4619 | MEDIUM | 6.5 | 0.7% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated ... |
| CVE-2020-4618 | MEDIUM | 4.9 | 1.1% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow a privileged user to cause a denial of service due to improper input vali... |
| CVE-2020-4617 | HIGH | 8.1 | 0.6% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute ... |
| CVE-2020-4616 | MEDIUM | 5.3 | 1.7% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could disclose sensitive username information to an attacker using a specially crafte... |
| CVE-2020-4615 | MEDIUM | 5.4 | 0.7% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2020-4614 | HIGH | 7.5 | 0.8% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to de... |
| CVE-2020-4613 | HIGH | 7.5 | 0.9% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to de... |
| CVE-2020-4612 | MEDIUM | 6.5 | 1.3% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to obtain sensitive information using a specially c... |
| CVE-2020-4611 | HIGH | 8.8 | 1.6% | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for... |
| CVE-2020-3977 | MEDIUM | 6.5 | 1.0% | Sep 22, 2020 | VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in ... |
| CVE-2020-23446 | MEDIUM | 5.3 | 1.5% | Sep 22, 2020 | Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API |
| CVE-2020-11857 | CRITICAL | 9.8 | 15.8% | Sep 22, 2020 | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The... |
| CVE-2020-11855 | HIGH | 7.8 | 1.3% | Sep 22, 2020 | An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The... |
| CVE-2020-8887 | HIGH | 7.5 | 1.5% | Sep 22, 2020 | Telestream Tektronix Medius before 10.7.5 and Sentry before 10.7.5 have a SQL injection vulnerability allowing an unauth... |
| CVE-2020-24619 | MEDIUM | 5.9 | 0.7% | Sep 22, 2020 | In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::Ver... |
| CVE-2020-7734 | HIGH | 8.2 | 1.3% | Sep 22, 2020 | All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column. |
| CVE-2020-6576 | HIGH | 8.8 | 1.6% | Sep 21, 2020 | Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially expl... |
| CVE-2020-6575 | HIGH | 8.3 | 1.4% | Sep 21, 2020 | Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process ... |
| CVE-2020-6574 | HIGH | 7.8 | 0.4% | Sep 21, 2020 | Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to... |
| CVE-2020-6573 | CRITICAL | 9.6 | 1.8% | Sep 21, 2020 | Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised... |
| CVE-2020-6571 | MEDIUM | 4.3 | 1.3% | Sep 21, 2020 | Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform doma... |
| CVE-2020-6570 | MEDIUM | 4.3 | 1.2% | Sep 21, 2020 | Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sen... |
| CVE-2020-6569 | MEDIUM | 6.3 | 1.3% | Sep 21, 2020 | Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the rend... |
| CVE-2020-6568 | MEDIUM | 6.5 | 1.5% | Sep 21, 2020 | Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote at... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now