2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15525 | MEDIUM | 5.3 | 1.1% | Jul 7, 2020 | GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint. |
| CVE-2020-15517 | MEDIUM | 5.4 | 0.6% | Jul 7, 2020 | The ke_search (aka Faceted Search) extension through 2.8.2, and 3.x through 3.1.3, for TYPO3 allows XSS. |
| CVE-2020-15516 | MEDIUM | 5.4 | 0.4% | Jul 7, 2020 | The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF. |
| CVE-2020-15514 | MEDIUM | 5.4 | 0.6% | Jul 7, 2020 | The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS. |
| CVE-2020-15513 | MEDIUM | 5.3 | 0.8% | Jul 7, 2020 | The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control. |
| CVE-2020-15509 | MEDIUM | 6.5 | 0.5% | Jul 7, 2020 | Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connec... |
| CVE-2020-15392 | MEDIUM | 5.3 | 1.2% | Jul 7, 2020 | A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recove... |
| CVE-2020-15367 | CRITICAL | 9.8 | 2.0% | Jul 7, 2020 | Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit th... |
| CVE-2020-10745 | HIGH | 7.5 | 3.9% | Jul 7, 2020 | A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios ... |
| CVE-2020-10730 | MEDIUM | 6.5 | 2.4% | Jul 7, 2020 | A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17... |
| CVE-2020-15567 | HIGH | 7.8 | 0.3% | Jul 7, 2020 | An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of ser... |
| CVE-2020-15566 | MEDIUM | 6.5 | 0.4% | Jul 7, 2020 | An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect err... |
| CVE-2020-15565 | HIGH | 8.8 | 0.4% | Jul 7, 2020 | An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of servic... |
| CVE-2020-15564 | MEDIUM | 6.5 | 0.4% | Jul 7, 2020 | An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a miss... |
| CVE-2020-15563 | MEDIUM | 6.5 | 0.4% | Jul 7, 2020 | An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted ... |
| CVE-2020-5600 | HIGH | 7.5 | 2.0% | Jul 7, 2020 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta... |
| CVE-2020-5599 | CRITICAL | 9.8 | 3.5% | Jul 7, 2020 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta... |
| CVE-2020-5598 | HIGH | 7.5 | 1.8% | Jul 7, 2020 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta... |
| CVE-2020-5597 | HIGH | 7.5 | 2.0% | Jul 7, 2020 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta... |
| CVE-2020-5596 | HIGH | 7.5 | 1.6% | Jul 7, 2020 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta... |
| CVE-2020-5595 | CRITICAL | 9.8 | 2.5% | Jul 7, 2020 | TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta... |
| CVE-2020-15507 | HIGH | 7.5 | 2.2% | Jul 7, 2020 | An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, ... |
| CVE-2020-15506 | CRITICAL | 9.8 | 2.8% | Jul 7, 2020 | An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,... |
| CVE-2020-15505 | CRITICAL | 9.8 | 99.7% | Jul 7, 2020 | A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, ... |
| CVE-2020-4077 | CRITICAL | 9.9 | 1.0% | Jul 7, 2020 | In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the mai... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now