2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25796 | HIGH | 7.5 | 1.6% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation, an unaligne... |
| CVE-2020-25795 | HIGH | 7.5 | 1.7% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, insert_from can h... |
| CVE-2020-25794 | HIGH | 7.5 | 1.7% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, clone can have a ... |
| CVE-2020-25793 | HIGH | 7.5 | 1.6% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is... |
| CVE-2020-25792 | HIGH | 7.5 | 2.8% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is... |
| CVE-2020-25791 | HIGH | 7.5 | 1.7% | Sep 19, 2020 | An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is... |
| CVE-2020-25790 | HIGH | 7.2 | 15.6% | Sep 19, 2020 | Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi... |
| CVE-2020-25789 | MEDIUM | 6.1 | 0.9% | Sep 19, 2020 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript in... |
| CVE-2020-25788 | HIGH | 8.1 | 1.2% | Sep 19, 2020 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mish... |
| CVE-2020-25787 | CRITICAL | 9.8 | 18.4% | Sep 19, 2020 | An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting... |
| CVE-2020-25786 | MEDIUM | 6.1 | 1.0% | Sep 19, 2020 | webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header.... |
| CVE-2020-5421 | MEDIUM | 6.5 | 10.7% | Sep 19, 2020 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versio... |
| CVE-2020-8253 | HIGH | 7.5 | 1.7% | Sep 18, 2020 | Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe... |
| CVE-2020-8252 | HIGH | 7.8 | 0.7% | Sep 18, 2020 | The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined th... |
| CVE-2020-8251 | HIGH | 7.5 | 8.8% | Sep 18, 2020 | Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can m... |
| CVE-2020-8247 | HIGH | 8.8 | 1.4% | Sep 18, 2020 | Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix AD... |
| CVE-2020-8246 | HIGH | 7.5 | 1.6% | Sep 18, 2020 | Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix AD... |
| CVE-2020-8245 | MEDIUM | 6.1 | 0.9% | Sep 18, 2020 | Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1... |
| CVE-2020-8237 | HIGH | 7.5 | 1.7% | Sep 18, 2020 | Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack. |
| CVE-2020-8225 | HIGH | 7.5 | 0.9% | Sep 18, 2020 | A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies ... |
| CVE-2020-8201 | HIGH | 7.4 | 5.1% | Sep 18, 2020 | Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspec... |
| CVE-2020-8200 | MEDIUM | 6.5 | 1.3% | Sep 18, 2020 | Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Mi... |
| CVE-2020-8158 | CRITICAL | 9.8 | 2.1% | Sep 18, 2020 | Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties... |
| CVE-2020-11861 | HIGH | 7.8 | 0.3% | Sep 18, 2020 | Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior t... |
| CVE-2020-9084 | MEDIUM | 6.5 | 0.2% | Sep 18, 2020 | Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now