2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5923 | MEDIUM | 5.4 | 0.5% | Aug 26, 2020 | In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1 and BIG-IQ ve... |
| CVE-2020-5922 | HIGH | 8.8 | 0.6% | Aug 26, 2020 | In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl RES... |
| CVE-2020-5920 | MEDIUM | 4.3 | 0.9% | Aug 26, 2020 | In versions 15.0.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a vulnerability in ... |
| CVE-2020-5919 | HIGH | 7.5 | 1.0% | Aug 26, 2020 | In versions 15.1.0-15.1.0.4, rendering of certain session variables by BIG-IP APM UI-based agents in an access profile c... |
| CVE-2020-5918 | HIGH | 7.5 | 1.0% | Aug 26, 2020 | In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.... |
| CVE-2020-5917 | MEDIUM | 5.9 | 0.5% | Aug 26, 2020 | In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.... |
| CVE-2020-5916 | MEDIUM | 6.8 | 0.5% | Aug 26, 2020 | In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged rol... |
| CVE-2020-5915 | MEDIUM | 6.1 | 0.6% | Aug 26, 2020 | In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.... |
| CVE-2020-5914 | HIGH | 7.5 | 1.0% | Aug 26, 2020 | In BIG-IP ASM versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-1... |
| CVE-2020-5913 | HIGH | 7.4 | 0.5% | Aug 26, 2020 | In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Client o... |
| CVE-2020-5912 | HIGH | 7.1 | 0.3% | Aug 26, 2020 | In BIG-IP versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.... |
| CVE-2020-16251 | HIGH | 8.2 | 3.1% | Aug 26, 2020 | HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vuln... |
| CVE-2020-16250 | HIGH | 8.2 | 1.5% | Aug 26, 2020 | HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vuln... |
| CVE-2020-15484 | HIGH | 7.5 | 0.8% | Aug 26, 2020 | An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system... |
| CVE-2020-13410 | HIGH | 7.5 | 2.2% | Aug 26, 2020 | An issue was discovered in MoscaJS Aedes 0.42.0. lib/write.js does not properly consider exceptions during the writing o... |
| CVE-2020-24316 | MEDIUM | 6.1 | 0.9% | Aug 26, 2020 | WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it ... |
| CVE-2020-24315 | HIGH | 7.5 | 2.0% | Aug 26, 2020 | Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to ... |
| CVE-2020-24008 | MEDIUM | 5.3 | 0.9% | Aug 26, 2020 | Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in me... |
| CVE-2020-24007 | CRITICAL | 9.8 | 1.6% | Aug 26, 2020 | Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerabili... |
| CVE-2020-19007 | MEDIUM | 5.4 | 0.5% | Aug 26, 2020 | Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code suppl... |
| CVE-2020-14498 | CRITICAL | 10 | 2.9% | Aug 26, 2020 | HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which ma... |
| CVE-2020-24314 | MEDIUM | 6.1 | 0.9% | Aug 26, 2020 | Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoin... |
| CVE-2020-24313 | MEDIUM | 6.1 | 1.2% | Aug 26, 2020 | Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the valu... |
| CVE-2020-24312 | HIGH | 7.5 | 16.3% | Aug 26, 2020 | mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htacce... |
| CVE-2020-15499 | MEDIUM | 6.1 | 0.6% | Aug 26, 2020 | An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now