2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13928 | MEDIUM | 6.1 | 2.6% | Sep 16, 2020 | Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitize... |
| CVE-2020-10748 | MEDIUM | 6.1 | 0.9% | Sep 16, 2020 | A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circ... |
| CVE-2020-10715 | MEDIUM | 4.3 | 0.9% | Sep 16, 2020 | A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft ... |
| CVE-2020-3990 | MEDIUM | 6.5 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerabil... |
| CVE-2020-3989 | LOW | 3.3 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability du... |
| CVE-2020-3988 | MEDIUM | 6.1 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ... |
| CVE-2020-3987 | MEDIUM | 6.1 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ... |
| CVE-2020-3986 | MEDIUM | 6.1 | 0.3% | Sep 16, 2020 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability ... |
| CVE-2020-3980 | MEDIUM | 6.7 | 0.3% | Sep 16, 2020 | VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide ... |
| CVE-2020-7532 | HIGH | 7.8 | 1.4% | Sep 16, 2020 | A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and pri... |
| CVE-2020-7531 | HIGH | 7.8 | 0.8% | Sep 16, 2020 | A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allow... |
| CVE-2020-7530 | HIGH | 8.8 | 1.2% | Sep 16, 2020 | A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows... |
| CVE-2020-7529 | MEDIUM | 5.5 | 0.9% | Sep 16, 2020 | A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAP... |
| CVE-2020-7528 | HIGH | 7.8 | 1.4% | Sep 16, 2020 | A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) w... |
| CVE-2020-4708 | MEDIUM | 5.3 | 1.0% | Sep 16, 2020 | IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Contr... |
| CVE-2020-4409 | HIGH | 8.2 | 0.9% | Sep 16, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbin... |
| CVE-2020-1748 | HIGH | 7.5 | 1.4% | Sep 16, 2020 | A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityMan... |
| CVE-2020-10758 | HIGH | 7.5 | 2.2% | Sep 16, 2020 | A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneous... |
| CVE-2020-25614 | CRITICAL | 9.8 | 1.9% | Sep 16, 2020 | xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause... |
| CVE-2020-24891 | — | — | — | Sep 16, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-24890 | MEDIUM | 5.5 | 1.6% | Sep 16, 2020 | libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in... |
| CVE-2020-24889 | HIGH | 7.8 | 1.4% | Sep 16, 2020 | A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp ... |
| CVE-2020-1710 | MEDIUM | 5.3 | 1.2% | Sep 16, 2020 | The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a ... |
| CVE-2020-14382 | HIGH | 7.8 | 1.2% | Sep 16, 2020 | A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, tha... |
| CVE-2020-10733 | HIGH | 7.3 | 0.5% | Sep 16, 2020 | The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now