2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-6112 | HIGH | 7.8 | 17.1% | Sep 17, 2020 | An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.... |
| CVE-2020-13948 | HIGH | 8.8 | 3.1% | Sep 17, 2020 | While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests v... |
| CVE-2020-8028 | CRITICAL | 9.3 | 0.4% | Sep 17, 2020 | A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Se... |
| CVE-2020-14181 | MEDIUM | 5.3 | 99.6% | Sep 17, 2020 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor... |
| CVE-2020-24377 | CRITICAL | 9.6 | 1.2% | Sep 16, 2020 | A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3. |
| CVE-2020-24376 | CRITICAL | 9.6 | 1.0% | Sep 16, 2020 | A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.... |
| CVE-2020-24374 | CRITICAL | 9.6 | 1.2% | Sep 16, 2020 | A DNS rebinding vulnerability in Freebox v5 before 1.5.29. |
| CVE-2020-24373 | HIGH | 8.8 | 0.5% | Sep 16, 2020 | A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3. |
| CVE-2020-20406 | MEDIUM | 5.4 | 0.7% | Sep 16, 2020 | A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 ... |
| CVE-2020-16233 | HIGH | 7.5 | 1.8% | Sep 16, 2020 | An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packe... |
| CVE-2020-14519 | HIGH | 7.5 | 0.6% | Sep 16, 2020 | This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are a... |
| CVE-2020-14517 | CRITICAL | 9.8 | 0.7% | Sep 16, 2020 | Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 ... |
| CVE-2020-14515 | HIGH | 7.5 | 0.8% | Sep 16, 2020 | CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in ... |
| CVE-2020-14513 | HIGH | 7.5 | 1.6% | Sep 16, 2020 | CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted licen... |
| CVE-2020-14509 | CRITICAL | 9.8 | 2.0% | Sep 16, 2020 | Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mecha... |
| CVE-2020-6781 | HIGH | 7.4 | 0.5% | Sep 16, 2020 | Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17... |
| CVE-2020-6146 | HIGH | 8.8 | 78.5% | Sep 16, 2020 | An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.3... |
| CVE-2020-1694 | MEDIUM | 4.9 | 1.6% | Sep 16, 2020 | A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-au... |
| CVE-2020-13259 | HIGH | 8.8 | 4.7% | Sep 16, 2020 | A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauth... |
| CVE-2020-10718 | HIGH | 7.5 | 1.4% | Sep 16, 2020 | A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed ... |
| CVE-2020-25040 | HIGH | 8.8 | 2.0% | Sep 16, 2020 | Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit contain... |
| CVE-2020-25039 | HIGH | 8.1 | 2.0% | Sep 16, 2020 | Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namesp... |
| CVE-2020-25015 | MEDIUM | 6.5 | 3.1% | Sep 16, 2020 | A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally... |
| CVE-2020-14348 | MEDIUM | 4.3 | 0.8% | Sep 16, 2020 | It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the us... |
| CVE-2020-14306 | HIGH | 8.8 | 1.3% | Sep 16, 2020 | An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions thr... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now