2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17366 | HIGH | 7.4 | 0.7% | Aug 5, 2020 | An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended acce... |
| CVE-2020-7298 | HIGH | 8.4 | 0.3% | Aug 5, 2020 | Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real tim... |
| CVE-2020-15132 | MEDIUM | 5.3 | 1.1% | Aug 5, 2020 | In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu ... |
| CVE-2020-15127 | HIGH | 7.5 | 1.4% | Aug 5, 2020 | In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, ... |
| CVE-2020-13404 | HIGH | 8.8 | 6.5% | Aug 5, 2020 | The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection. |
| CVE-2020-16254 | MEDIUM | 6.1 | 0.8% | Aug 5, 2020 | The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute). |
| CVE-2020-15113 | HIGH | 7.1 | 0.2% | Aug 5, 2020 | In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory pa... |
| CVE-2020-15112 | MEDIUM | 6.5 | 1.3% | Aug 5, 2020 | In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in t... |
| CVE-2020-15106 | MEDIUM | 6.5 | 1.3% | Aug 5, 2020 | In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is st... |
| CVE-2020-16192 | MEDIUM | 6.1 | 0.7% | Aug 5, 2020 | LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parame... |
| CVE-2020-17364 | MEDIUM | 6.1 | 0.8% | Aug 5, 2020 | USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs. |
| CVE-2020-8607 | MEDIUM | 6.7 | 0.7% | Aug 5, 2020 | An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific ro... |
| CVE-2020-5609 | CRITICAL | 9.8 | 2.1% | Aug 5, 2020 | Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, C... |
| CVE-2020-5608 | CRITICAL | 9.8 | 1.6% | Aug 5, 2020 | CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, B... |
| CVE-2020-4481 | HIGH | 8.2 | 2.0% | Aug 5, 2020 | IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE... |
| CVE-2020-4243 | LOW | 3.7 | 0.9% | Aug 5, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 Virtual Appliance could allow a remote attacker to obtain sensit... |
| CVE-2020-17353 | CRITICAL | 9.8 | 2.4% | Aug 5, 2020 | scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restri... |
| CVE-2020-16253 | HIGH | 8.1 | 0.5% | Aug 5, 2020 | The PgHero gem through 2.6.0 for Ruby allows CSRF. |
| CVE-2020-16252 | MEDIUM | 4.3 | 0.4% | Aug 5, 2020 | The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF. |
| CVE-2020-14347 | MEDIUM | 5.5 | 0.4% | Aug 5, 2020 | A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X... |
| CVE-2020-14344 | MEDIUM | 6.7 | 0.5% | Aug 5, 2020 | An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in li... |
| CVE-2020-13921 | CRITICAL | 9.8 | 33.5% | Aug 5, 2020 | **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the w... |
| CVE-2020-13819 | MEDIUM | 6.1 | 0.9% | Aug 5, 2020 | Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. |
| CVE-2020-13151 | CRITICAL | 9.8 | 86.7% | Aug 5, 2020 | Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)... |
| CVE-2020-15109 | MEDIUM | 5.3 | 0.9% | Aug 4, 2020 | In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering addre... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now