2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9288 | MEDIUM | 5.4 | 0.9% | Jun 22, 2020 | An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a ... |
| CVE-2020-6644 | HIGH | 8.1 | 1.0% | Jun 22, 2020 | An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpi... |
| CVE-2020-4070 | MEDIUM | 5.4 | 0.5% | Jun 22, 2020 | In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A... |
| CVE-2020-4068 | CRITICAL | 9.8 | 1.3% | Jun 22, 2020 | In APNSwift 1.0.0, calling APNSwiftSigner.sign(digest:) is likely to result in a heap buffer overflow. This has been fix... |
| CVE-2020-4066 | HIGH | 7.2 | 1.6% | Jun 22, 2020 | In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are un... |
| CVE-2020-4062 | CRITICAL | 9 | 1.4% | Jun 22, 2020 | In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the ... |
| CVE-2020-4060 | MEDIUM | 5 | 0.9% | Jun 22, 2020 | In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug i... |
| CVE-2020-13887 | HIGH | 8.8 | 2.4% | Jun 22, 2020 | documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to... |
| CVE-2020-13279 | HIGH | 8.6 | 1.2% | Jun 22, 2020 | Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system |
| CVE-2020-13888 | MEDIUM | 5.4 | 0.5% | Jun 22, 2020 | Kordil EDMS through 2.2.60rc3 allows stored XSS in users_edit.php, users_management_edit.php, and user_management.php. |
| CVE-2020-8933 | HIGH | 7.8 | 0.4% | Jun 22, 2020 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on... |
| CVE-2020-8907 | HIGH | 7.8 | 0.3% | Jun 22, 2020 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on... |
| CVE-2020-8903 | HIGH | 7.8 | 0.3% | Jun 22, 2020 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on... |
| CVE-2020-14461 | HIGH | 8.6 | 9.5% | Jun 22, 2020 | Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI. |
| CVE-2020-14204 | HIGH | 8.2 | 1.9% | Jun 22, 2020 | In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local f... |
| CVE-2020-14203 | HIGH | 8.8 | 0.5% | Jun 22, 2020 | WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users ... |
| CVE-2020-14202 | MEDIUM | 6.1 | 0.7% | Jun 22, 2020 | WebFOCUS Business Intelligence 8.0 (SP6) was prone to XSS via arbitrary URL parameters. |
| CVE-2020-14969 | HIGH | 7.5 | 1.3% | Jun 22, 2020 | app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the att... |
| CVE-2020-14968 | CRITICAL | 9.8 | 2.9% | Jun 22, 2020 | An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does... |
| CVE-2020-14967 | CRITICAL | 9.8 | 2.6% | Jun 22, 2020 | An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation... |
| CVE-2020-14966 | HIGH | 7.5 | 1.1% | Jun 22, 2020 | An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signature... |
| CVE-2020-8102 | HIGH | 8.8 | 1.1% | Jun 22, 2020 | Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an ex... |
| CVE-2020-7262 | MEDIUM | 5.5 | 0.7% | Jun 22, 2020 | Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view... |
| CVE-2020-3676 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdr... |
| CVE-2020-3665 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firm... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now