2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13176 | MEDIUM | 6.1 | 0.8% | Aug 11, 2020 | The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to ... |
| CVE-2020-13175 | HIGH | 7.5 | 1.7% | Aug 11, 2020 | The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to ... |
| CVE-2020-13174 | MEDIUM | 6.1 | 0.7% | Aug 11, 2020 | The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HT... |
| CVE-2020-17466 | CRITICAL | 9.8 | 1.5% | Aug 11, 2020 | Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redir... |
| CVE-2020-17448 | HIGH | 7.8 | 2.3% | Aug 11, 2020 | Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechan... |
| CVE-2020-17368 | CRITICAL | 9.8 | 4.1% | Aug 11, 2020 | Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may ... |
| CVE-2020-17367 | HIGH | 7.8 | 1.5% | Aug 11, 2020 | Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to comm... |
| CVE-2020-16092 | LOW | 3.8 | 0.4% | Aug 11, 2020 | In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e an... |
| CVE-2020-15597 | MEDIUM | 5.4 | 0.5% | Aug 11, 2020 | SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment fi... |
| CVE-2020-13124 | HIGH | 8.8 | 4.6% | Aug 11, 2020 | SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an a... |
| CVE-2020-11552 | CRITICAL | 9.8 | 7.4% | Aug 11, 2020 | An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not ... |
| CVE-2020-14324 | CRITICAL | 9.1 | 2.5% | Aug 11, 2020 | A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS... |
| CVE-2020-14313 | MEDIUM | 4.3 | 0.9% | Aug 11, 2020 | An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker... |
| CVE-2020-14296 | HIGH | 7.1 | 0.6% | Aug 11, 2020 | Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible T... |
| CVE-2020-10780 | MEDIUM | 6.3 | 0.7% | Aug 11, 2020 | Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as ... |
| CVE-2020-14325 | CRITICAL | 9.1 | 1.1% | Aug 11, 2020 | Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious at... |
| CVE-2020-10783 | HIGH | 8.3 | 1.0% | Aug 11, 2020 | Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group ... |
| CVE-2020-10779 | MEDIUM | 6.5 | 0.8% | Aug 11, 2020 | Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypas... |
| CVE-2020-10778 | MEDIUM | 6 | 0.9% | Aug 11, 2020 | In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled a... |
| CVE-2020-10777 | MEDIUM | 5.4 | 0.7% | Aug 11, 2020 | A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this... |
| CVE-2020-4486 | HIGH | 8.1 | 1.5% | Aug 11, 2020 | IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw af... |
| CVE-2020-4485 | MEDIUM | 6.5 | 1.5% | Aug 11, 2020 | IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an at... |
| CVE-2020-9079 | HIGH | 8.8 | 0.4% | Aug 11, 2020 | FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protectio... |
| CVE-2020-16278 | MEDIUM | 6.1 | 0.6% | Aug 10, 2020 | A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could... |
| CVE-2020-16277 | HIGH | 8.8 | 1.2% | Aug 10, 2020 | An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, au... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now