2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7127 | CRITICAL | 9.8 | 1.8% | Oct 26, 2020 | A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Pri... |
| CVE-2020-7124 | CRITICAL | 9.8 | 1.4% | Oct 26, 2020 | A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
| CVE-2020-18766 | CRITICAL | 9.6 | 1.1% | Oct 26, 2020 | A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands. |
| CVE-2020-27678 | CRITICAL | 9.8 | 1.4% | Oct 26, 2020 | An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and Sm... |
| CVE-2020-25483 | CRITICAL | 9.8 | 8.6% | Oct 23, 2020 | An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an atta... |
| CVE-2020-25466 | CRITICAL | 9.8 | 3.0% | Oct 23, 2020 | A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on ... |
| CVE-2020-15684 | CRITICAL | 9.8 | 1.3% | Oct 22, 2020 | Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corru... |
| CVE-2020-15683 | CRITICAL | 9.8 | 2.6% | Oct 22, 2020 | Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of... |
| CVE-2020-9920 | CRITICAL | 9.1 | 1.8% | Oct 22, 2020 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Cat... |
| CVE-2020-9906 | CRITICAL | 9.1 | 4.7% | Oct 22, 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6,... |
| CVE-2020-27664 | CRITICAL | 9.8 | 2.3% | Oct 22, 2020 | admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality. |
| CVE-2020-9898 | CRITICAL | 9.8 | 1.3% | Oct 22, 2020 | This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.... |
| CVE-2020-9868 | CRITICAL | 9.1 | 1.0% | Oct 22, 2020 | A certificate validation issue existed when processing administrator added certificates. This issue was addressed with i... |
| CVE-2020-15906 | CRITICAL | 9.8 | 27.4% | Oct 22, 2020 | tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. |
| CVE-2020-27195 | CRITICAL | 9.1 | 1.5% | Oct 22, 2020 | HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using eithe... |
| CVE-2020-27619 | CRITICAL | 9.8 | 8.2% | Oct 22, 2020 | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via H... |
| CVE-2020-27615 | CRITICAL | 9.8 | 53.6% | Oct 21, 2020 | The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa... |
| CVE-2020-15240 | CRITICAL | 9.1 | 0.8% | Oct 21, 2020 | omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_... |
| CVE-2020-7750 | CRITICAL | 9.6 | 6.1% | Oct 21, 2020 | This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not e... |
| CVE-2020-27605 | CRITICAL | 9.8 | 1.2% | Oct 21, 2020 | BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject ... |
| CVE-2020-14882 | CRITICAL | 9.8 | 100.0% | Oct 21, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions... |
| CVE-2020-14876 | CRITICAL | 9.1 | 2.8% | Oct 21, 2020 | Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface). Supported v... |
| CVE-2020-14875 | CRITICAL | 9.1 | 2.2% | Oct 21, 2020 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supporte... |
| CVE-2020-14871 | CRITICAL | 10 | 80.3% | Oct 21, 2020 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve... |
| CVE-2020-14859 | CRITICAL | 9.8 | 3.8% | Oct 21, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now