2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15168 | MEDIUM | 5.3 | 1.7% | Sep 10, 2020 | node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means ... |
| CVE-2020-13920 | MEDIUM | 5.9 | 4.6% | Sep 10, 2020 | Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi"... |
| CVE-2020-11998 | CRITICAL | 9.8 | 51.2% | Sep 10, 2020 | A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnect... |
| CVE-2020-15024 | MEDIUM | 5.5 | 0.3% | Sep 10, 2020 | An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562... |
| CVE-2020-9743 | MEDIUM | 6.1 | 2.0% | Sep 10, 2020 | AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by... |
| CVE-2020-9742 | MEDIUM | 5.4 | 1.8% | Sep 10, 2020 | AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability... |
| CVE-2020-9741 | MEDIUM | 5.4 | 1.9% | Sep 10, 2020 | The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability ... |
| CVE-2020-9740 | MEDIUM | 5.4 | 1.9% | Sep 10, 2020 | AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by... |
| CVE-2020-9738 | MEDIUM | 4.8 | 1.7% | Sep 10, 2020 | AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by... |
| CVE-2020-9737 | MEDIUM | 4.8 | 1.7% | Sep 10, 2020 | AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by... |
| CVE-2020-9736 | MEDIUM | 4.8 | 1.8% | Sep 10, 2020 | AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by... |
| CVE-2020-9735 | MEDIUM | 4.8 | 1.8% | Sep 10, 2020 | AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by... |
| CVE-2020-9734 | MEDIUM | 5.4 | 1.9% | Sep 10, 2020 | The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability ... |
| CVE-2020-9733 | HIGH | 7.5 | 3.8% | Sep 10, 2020 | An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high ... |
| CVE-2020-9732 | CRITICAL | 9 | 2.8% | Sep 10, 2020 | The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability... |
| CVE-2020-4578 | MEDIUM | 5.4 | 0.7% | Sep 10, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2020-24582 | MEDIUM | 6.1 | 0.7% | Sep 10, 2020 | Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user ... |
| CVE-2020-17408 | HIGH | 7.5 | 74.0% | Sep 10, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressClu... |
| CVE-2020-14198 | HIGH | 7.5 | 3.4% | Sep 10, 2020 | Bitcoin Core 0.20.0 allows remote denial of service. |
| CVE-2020-10773 | MEDIUM | 4.4 | 0.4% | Sep 10, 2020 | A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incor... |
| CVE-2020-8758 | CRITICAL | 9.8 | 1.7% | Sep 10, 2020 | Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, ... |
| CVE-2020-6097 | HIGH | 7.5 | 2.4% | Sep 10, 2020 | An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1... |
| CVE-2020-5780 | MEDIUM | 5.3 | 1.6% | Sep 10, 2020 | Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to ve... |
| CVE-2020-25221 | HIGH | 7.8 | 0.7% | Sep 10, 2020 | get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorr... |
| CVE-2020-24739 | MEDIUM | 6.5 | 0.4% | Sep 10, 2020 | A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TO... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now