2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7658MEDIUM6.1meinheld prior to 1.0.2 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks mi...
CVE-2020-11077HIGH7.5In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a...
CVE-2020-11076HIGH7.5In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-enco...
CVE-2020-10711MEDIUM5.9A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occu...
CVE-2020-8789MEDIUM5.4Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.
CVE-2020-7813CRITICAL9.8Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allo...
CVE-2020-6091CRITICAL9.1An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN...
CVE-2020-1956HIGH8.8Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the ...
CVE-2020-3344MEDIUM5.5A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software c...
CVE-2020-3343MEDIUM5.5A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software c...
CVE-2020-3314MEDIUM6.1A vulnerability in the file scan process of Cisco AMP for Endpoints Mac Connector Software could cause the scan engine t...
CVE-2020-3280CRITICAL9.8A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allo...
CVE-2020-3272HIGH7.5A vulnerability in the DHCP server of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to c...
CVE-2020-3184HIGH7.2A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an ...
CVE-2020-13384HIGH8.8Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=file...
CVE-2020-1195LOW3.1An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly...
CVE-2020-1192HIGH7.8A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings fr...
CVE-2020-1191HIGH7.8An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m...
CVE-2020-1190HIGH7.8An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m...
CVE-2020-1189HIGH7.8An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m...
CVE-2020-1188HIGH7.8An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m...
CVE-2020-1187HIGH7.8An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m...
CVE-2020-1186HIGH7.8An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m...
CVE-2020-1185HIGH7.8An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m...
CVE-2020-1184HIGH7.8An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now