2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-16847 | MEDIUM | 6.1 | 0.6% | Aug 4, 2020 | Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in ... |
| CVE-2020-15135 | HIGH | 7.6 | 0.7% | Aug 4, 2020 | save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Token... |
| CVE-2020-16843 | MEDIUM | 5.9 | 1.7% | Aug 4, 2020 | In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. ... |
| CVE-2020-15956 | HIGH | 7.5 | 10.5% | Aug 4, 2020 | ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer... |
| CVE-2020-15944 | MEDIUM | 5.4 | 1.3% | Aug 4, 2020 | An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is ... |
| CVE-2020-15943 | HIGH | 8.1 | 1.8% | Aug 4, 2020 | An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possibl... |
| CVE-2020-13522 | HIGH | 7.1 | 0.5% | Aug 4, 2020 | An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially craf... |
| CVE-2020-16203 | HIGH | 7.8 | 1.9% | Aug 4, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited ... |
| CVE-2020-16201 | LOW | 3.3 | 1.4% | Aug 4, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilitie... |
| CVE-2020-16199 | HIGH | 7.8 | 10.2% | Aug 4, 2020 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulne... |
| CVE-2020-16134 | HIGH | 8 | 0.8% | Aug 4, 2020 | An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet... |
| CVE-2020-13523 | LOW | 3.3 | 0.5% | Aug 4, 2020 | An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially c... |
| CVE-2020-4631 | MEDIUM | 5.5 | 0.2% | Aug 4, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned acce... |
| CVE-2020-4542 | MEDIUM | 5.4 | 0.6% | Aug 4, 2020 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-4525 | MEDIUM | 5.4 | 0.6% | Aug 4, 2020 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-4459 | CRITICAL | 9.8 | 1.0% | Aug 4, 2020 | IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses ... |
| CVE-2020-4410 | MEDIUM | 4.3 | 1.0% | Aug 4, 2020 | IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to send a specially crafted HTTP GET ... |
| CVE-2020-4396 | MEDIUM | 5.4 | 0.6% | Aug 4, 2020 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-7823 | HIGH | 7.8 | 1.2% | Aug 4, 2020 | DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandle... |
| CVE-2020-7822 | HIGH | 7.8 | 1.2% | Aug 4, 2020 | DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishand... |
| CVE-2020-6012 | HIGH | 7.4 | 0.5% | Aug 4, 2020 | ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sop... |
| CVE-2020-15467 | HIGH | 8.8 | 3.2% | Aug 4, 2020 | The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticat... |
| CVE-2020-5617 | HIGH | 7.8 | 0.3% | Aug 4, 2020 | Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unaut... |
| CVE-2020-5616 | CRITICAL | 9.8 | 3.1% | Aug 4, 2020 | [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Cale... |
| CVE-2020-5615 | HIGH | 8.8 | 0.7% | Aug 4, 2020 | Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now