2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2002 | HIGH | 8.1 | 1.3% | May 13, 2020 | An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Al... |
| CVE-2020-2001 | CRITICAL | 9.8 | 1.3% | May 13, 2020 | An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that ... |
| CVE-2020-1998 | HIGH | 8.8 | 0.9% | May 13, 2020 | An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of t... |
| CVE-2020-1997 | MEDIUM | 6.1 | 0.9% | May 13, 2020 | An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to spec... |
| CVE-2020-1996 | MEDIUM | 5.3 | 0.9% | May 13, 2020 | A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthentica... |
| CVE-2020-1995 | MEDIUM | 4.9 | 1.1% | May 13, 2020 | A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a re... |
| CVE-2020-1994 | MEDIUM | 4.4 | 0.2% | May 13, 2020 | A predictable temporary file vulnerability in PAN-OS allows a local authenticated user with shell access to corrupt arbi... |
| CVE-2020-1993 | MEDIUM | 5.4 | 0.4% | May 13, 2020 | The GlobalProtect Portal feature in PAN-OS does not set a new session identifier after a successful user login, which al... |
| CVE-2020-1714 | HIGH | 8.8 | 2.6% | May 13, 2020 | A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without typ... |
| CVE-2020-11073 | HIGH | 7.8 | 0.5% | May 13, 2020 | In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could... |
| CVE-2020-11070 | MEDIUM | 5.4 | 0.5% | May 13, 2020 | The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invali... |
| CVE-2020-12832 | CRITICAL | 9.8 | 7.1% | May 13, 2020 | WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files be... |
| CVE-2020-12831 | MEDIUM | 5.3 | 1.4% | May 13, 2020 | An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, th... |
| CVE-2020-5407 | HIGH | 8.8 | 1.2% | May 13, 2020 | Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during... |
| CVE-2020-9502 | CRITICAL | 9.8 | 1.7% | May 13, 2020 | Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user... |
| CVE-2020-9501 | MEDIUM | 5.5 | 0.3% | May 13, 2020 | Attackers can obtain Cloud Key information from the Dahua Web P2P control in specific ways. Cloud Key is used to authent... |
| CVE-2020-7455 | MEDIUM | 5.5 | 0.5% | May 13, 2020 | In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3... |
| CVE-2020-7454 | CRITICAL | 9.8 | 2.7% | May 13, 2020 | In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3... |
| CVE-2020-5838 | MEDIUM | 4.8 | 0.7% | May 13, 2020 | Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of is... |
| CVE-2020-8020 | MEDIUM | 6.1 | 0.9% | May 13, 2020 | A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attacker... |
| CVE-2020-12763 | CRITICAL | 9.8 | 3.4% | May 13, 2020 | TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow i... |
| CVE-2020-12427 | HIGH | 8.8 | 0.5% | May 13, 2020 | The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF,... |
| CVE-2020-4312 | MEDIUM | 4.3 | 0.8% | May 13, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 trough 6.0.3.1 could allow an authenticated user to obtain sensitiv... |
| CVE-2020-12742 | MEDIUM | 6.1 | 1.1% | May 13, 2020 | The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols. |
| CVE-2020-12700 | MEDIUM | 4.3 | 0.8% | May 13, 2020 | The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now