2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4405 | MEDIUM | 4.3 | 0.9% | Jul 27, 2020 | IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due t... |
| CVE-2020-15593 | HIGH | 7.8 | 0.4% | Jul 27, 2020 | SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Win... |
| CVE-2020-15592 | HIGH | 7.5 | 1.9% | Jul 27, 2020 | SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an exec... |
| CVE-2020-9251 | LOW | 2.4 | 0.2% | Jul 27, 2020 | HUAWEI Mate 20 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have an improper authorization vulnerabil... |
| CVE-2020-9077 | LOW | 3.3 | 0.5% | Jul 27, 2020 | HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. ... |
| CVE-2020-11110 | MEDIUM | 5.4 | 9.6% | Jul 27, 2020 | Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an a... |
| CVE-2020-7695 | MEDIUM | 5.3 | 1.3% | Jul 27, 2020 | Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP head... |
| CVE-2020-7694 | HIGH | 7.5 | 1.3% | Jul 27, 2020 | This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape se... |
| CVE-2020-5611 | HIGH | 8.8 | 1.2% | Jul 27, 2020 | Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attacker... |
| CVE-2020-15954 | MEDIUM | 6.5 | 0.7% | Jul 27, 2020 | KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encrypt... |
| CVE-2020-15953 | HIGH | 7.4 | 2.4% | Jul 27, 2020 | LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affe... |
| CVE-2020-7687 | HIGH | 7.5 | 1.8% | Jul 25, 2020 | This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in ind... |
| CVE-2020-7686 | HIGH | 7.5 | 1.8% | Jul 25, 2020 | This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation insid... |
| CVE-2020-7683 | HIGH | 7.5 | 1.8% | Jul 25, 2020 | This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed... |
| CVE-2020-7682 | HIGH | 7.5 | 1.7% | Jul 25, 2020 | This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in i... |
| CVE-2020-7681 | HIGH | 7.5 | 1.7% | Jul 25, 2020 | This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in inde... |
| CVE-2020-10614 | MEDIUM | 4.8 | 0.9% | Jul 25, 2020 | In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision dat... |
| CVE-2020-10604 | HIGH | 7.5 | 2.1% | Jul 25, 2020 | In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager s... |
| CVE-2020-12812 | CRITICAL | 9.8 | 49.3% | Jul 24, 2020 | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a us... |
| CVE-2020-10610 | HIGH | 7.8 | 0.4% | Jul 24, 2020 | In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exp... |
| CVE-2020-10608 | HIGH | 7.8 | 0.2% | Jul 24, 2020 | In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity che... |
| CVE-2020-10606 | HIGH | 7.8 | 0.3% | Jul 24, 2020 | In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected ... |
| CVE-2020-10602 | MEDIUM | 5.3 | 0.9% | Jul 24, 2020 | In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due... |
| CVE-2020-10600 | HIGH | 7.1 | 0.8% | Jul 24, 2020 | An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. T... |
| CVE-2020-8207 | HIGH | 8.8 | 2.1% | Jul 24, 2020 | Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code exe... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now