2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15525MEDIUM5.3GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
CVE-2020-15517MEDIUM5.4The ke_search (aka Faceted Search) extension through 2.8.2, and 3.x through 3.1.3, for TYPO3 allows XSS.
CVE-2020-15516MEDIUM5.4The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.
CVE-2020-15514MEDIUM5.4The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS.
CVE-2020-15513MEDIUM5.3The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.
CVE-2020-15509MEDIUM6.5Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connec...
CVE-2020-15392MEDIUM5.3A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recove...
CVE-2020-15367CRITICAL9.8Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit th...
CVE-2020-10745HIGH7.5A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios ...
CVE-2020-10730MEDIUM6.5A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17...
CVE-2020-15567HIGH7.8An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of ser...
CVE-2020-15566MEDIUM6.5An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect err...
CVE-2020-15565HIGH8.8An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of servic...
CVE-2020-15564MEDIUM6.5An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a miss...
CVE-2020-15563MEDIUM6.5An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted ...
CVE-2020-5600HIGH7.5TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta...
CVE-2020-5599CRITICAL9.8TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta...
CVE-2020-5598HIGH7.5TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta...
CVE-2020-5597HIGH7.5TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta...
CVE-2020-5596HIGH7.5TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta...
CVE-2020-5595CRITICAL9.8TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier insta...
CVE-2020-15507HIGH7.5An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, ...
CVE-2020-15506CRITICAL9.8An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,...
CVE-2020-15505CRITICAL9.8A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, ...
CVE-2020-4077CRITICAL9.9In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the mai...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now