2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3186 | MEDIUM | 5.3 | 1.3% | May 6, 2020 | A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow... |
| CVE-2020-3179 | HIGH | 7.5 | 1.9% | May 6, 2020 | A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defens... |
| CVE-2020-3178 | MEDIUM | 6.1 | 0.8% | May 6, 2020 | Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance ... |
| CVE-2020-3125 | CRITICAL | 9.8 | 2.4% | May 6, 2020 | A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow a... |
| CVE-2020-7921 | MEDIUM | 5.3 | 0.7% | May 6, 2020 | Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem perm... |
| CVE-2020-12108 | MEDIUM | 6.5 | 2.7% | May 6, 2020 | /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. |
| CVE-2020-6861 | MEDIUM | 5.5 | 0.4% | May 6, 2020 | A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attac... |
| CVE-2020-4446 | MEDIUM | 4.3 | 0.9% | May 6, 2020 | IBM Business Process Manager 8.0, 8.5, and 8.6 and IBM Business Automation Workflow 18.0 and 19.0 could allow a remote a... |
| CVE-2020-4421 | MEDIUM | 5.4 | 0.7% | May 6, 2020 | IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spo... |
| CVE-2020-4384 | MEDIUM | 5.4 | 0.6% | May 6, 2020 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2020-10704 | HIGH | 7.5 | 3.5% | May 6, 2020 | A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain request... |
| CVE-2020-10693 | MEDIUM | 5.3 | 2.3% | May 6, 2020 | A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invali... |
| CVE-2020-7806 | CRITICAL | 9.8 | 0.7% | May 6, 2020 | Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supporte... |
| CVE-2020-6094 | HIGH | 8.8 | 3.6% | May 6, 2020 | An exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Acc... |
| CVE-2020-6082 | HIGH | 8.8 | 3.6% | May 6, 2020 | An exploitable out-of-bounds write vulnerability exists in the ico_read function of the igcore19d.dll library of Accusof... |
| CVE-2020-6076 | HIGH | 8.8 | 3.6% | May 6, 2020 | An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll ICO icoread parser of the Accusoft ImageGea... |
| CVE-2020-6075 | HIGH | 8.8 | 3.6% | May 6, 2020 | An exploitable out-of-bounds write vulnerability exists in the store_data_buffer function of the igcore19d.dll library o... |
| CVE-2020-4092 | MEDIUM | 5.3 | 0.3% | May 6, 2020 | "If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clea... |
| CVE-2020-2189 | HIGH | 8.8 | 2.3% | May 6, 2020 | Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of ar... |
| CVE-2020-2188 | MEDIUM | 4.3 | 0.6% | May 6, 2020 | A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Ov... |
| CVE-2020-2187 | MEDIUM | 5.6 | 0.4% | May 6, 2020 | Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostn... |
| CVE-2020-2186 | MEDIUM | 4.3 | 0.6% | May 6, 2020 | A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision... |
| CVE-2020-2185 | MEDIUM | 5.6 | 0.7% | May 6, 2020 | Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the... |
| CVE-2020-2184 | MEDIUM | 4.3 | 44.5% | May 6, 2020 | A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipul... |
| CVE-2020-2183 | MEDIUM | 6.5 | 0.9% | May 6, 2020 | Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifact... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now