2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14528 | MEDIUM | 6.1 | 1.0% | Jul 15, 2020 | Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Acces... |
| CVE-2020-14527 | MEDIUM | 5.9 | 1.1% | Jul 15, 2020 | Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Acces... |
| CVE-2020-8203 | HIGH | 7.4 | 5.2% | Jul 15, 2020 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. |
| CVE-2020-8178 | CRITICAL | 9.8 | 3.6% | Jul 15, 2020 | Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks. |
| CVE-2020-15572 | HIGH | 7.5 | 1.4% | Jul 15, 2020 | Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor ... |
| CVE-2020-9496 | MEDIUM | 6.1 | 98.9% | Jul 15, 2020 | XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 |
| CVE-2020-15700 | MEDIUM | 6.3 | 0.6% | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer c... |
| CVE-2020-15699 | MEDIUM | 5.3 | 0.7% | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result i... |
| CVE-2020-15698 | MEDIUM | 5.3 | 1.6% | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Re... |
| CVE-2020-15697 | MEDIUM | 4.3 | 1.0% | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified b... |
| CVE-2020-15696 | MEDIUM | 6.1 | 3.2% | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random... |
| CVE-2020-15695 | MEDIUM | 6.3 | 0.6% | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy ca... |
| CVE-2020-13923 | MEDIUM | 5.3 | 5.0% | Jul 15, 2020 | IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04 |
| CVE-2020-7292 | MEDIUM | 4.3 | 0.9% | Jul 15, 2020 | Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attac... |
| CVE-2020-5765 | MEDIUM | 5.4 | 1.1% | Jul 15, 2020 | Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during sc... |
| CVE-2020-4100 | MEDIUM | 4.4 | 0.3% | Jul 15, 2020 | "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which comp... |
| CVE-2020-14511 | CRITICAL | 9.8 | 1.4% | Jul 15, 2020 | Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server o... |
| CVE-2020-14503 | CRITICAL | 9.8 | 3.5% | Jul 15, 2020 | Advantech iView, versions 5.6 and prior, has an improper input validation vulnerability. Successful exploitation of this... |
| CVE-2020-14501 | CRITICAL | 9.8 | 1.7% | Jul 15, 2020 | Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successfu... |
| CVE-2020-14499 | HIGH | 7.5 | 1.7% | Jul 15, 2020 | Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this v... |
| CVE-2020-14507 | CRITICAL | 9.8 | 4.9% | Jul 15, 2020 | Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an at... |
| CVE-2020-14505 | CRITICAL | 9.8 | 7.0% | Jul 15, 2020 | Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command ... |
| CVE-2020-14497 | CRITICAL | 9.8 | 4.9% | Jul 15, 2020 | Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use ... |
| CVE-2020-1481 | HIGH | 8.8 | 23.6% | Jul 14, 2020 | A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source cod... |
| CVE-2020-1469 | HIGH | 7.5 | 4.8% | Jul 14, 2020 | A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now