2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1817 | HIGH | 7.8 | 0.2% | Apr 30, 2020 | Huawei PCManager with versions earlier than 10.0.1.36 has a privilege escalation vulnerability. Due to improper permissi... |
| CVE-2020-11025 | MEDIUM | 5.4 | 1.5% | Apr 30, 2020 | In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer al... |
| CVE-2020-5893 | LOW | 3.7 | 0.6% | Apr 30, 2020 | In versions 7.1.5-7.1.8, when a user connects to a VPN using BIG-IP Edge Client over an unsecure network, BIG-IP Edge Cl... |
| CVE-2020-5891 | HIGH | 7.5 | 1.2% | Apr 30, 2020 | On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, undisclosed HTTP/2 requests can lead to a denial of ser... |
| CVE-2020-5889 | MEDIUM | 5.4 | 0.7% | Apr 30, 2020 | On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP... |
| CVE-2020-5887 | CRITICAL | 9.1 | 1.8% | Apr 30, 2020 | On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism fo... |
| CVE-2020-5886 | CRITICAL | 9.1 | 0.8% | Apr 30, 2020 | On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems setup for connection ... |
| CVE-2020-5885 | CRITICAL | 9.1 | 0.8% | Apr 30, 2020 | On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1, BIG-IP systems set up for connection... |
| CVE-2020-5884 | CRITICAL | 9.1 | 1.5% | Apr 30, 2020 | On versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.4, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the default deploym... |
| CVE-2020-5883 | HIGH | 7.5 | 1.3% | Apr 30, 2020 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, when a virtual server is configured with H... |
| CVE-2020-5882 | HIGH | 7.5 | 1.0% | Apr 30, 2020 | On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5, and 11.6.1-11.6.5.1, under certain condition... |
| CVE-2020-5881 | HIGH | 7.5 | 1.3% | Apr 30, 2020 | On versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when the BIG-IP Virtual Edition (VE) is configured wi... |
| CVE-2020-5880 | HIGH | 7.1 | 1.3% | Apr 30, 2020 | Om BIG-IP 15.0.0-15.0.1.3 and 14.1.0-14.1.2.3, the restjavad process may expose a way for attackers to upload arbitrary ... |
| CVE-2020-5879 | HIGH | 7.5 | 0.8% | Apr 30, 2020 | On BIG-IP ASM 11.6.1-11.6.5.1, under certain configurations, the BIG-IP system sends data plane traffic to back-end serv... |
| CVE-2020-5878 | HIGH | 7.5 | 1.0% | Apr 30, 2020 | On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.3, Traffic Management Microkernel (TMM) may restart on B... |
| CVE-2020-5877 | HIGH | 7.5 | 1.3% | Apr 30, 2020 | On BIG-IP 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, malformed input to th... |
| CVE-2020-5876 | HIGH | 8.1 | 0.6% | Apr 30, 2020 | On BIG-IP 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a race condition exis... |
| CVE-2020-5875 | HIGH | 7.5 | 1.3% | Apr 30, 2020 | On BIG-IP 15.0.0-15.0.1 and 14.1.0-14.1.2.3, under certain conditions, the Traffic Management Microkernel (TMM) may gene... |
| CVE-2020-5874 | HIGH | 7.5 | 1.3% | Apr 30, 2020 | On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifi... |
| CVE-2020-5873 | HIGH | 7.2 | 1.4% | Apr 30, 2020 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a us... |
| CVE-2020-7136 | CRITICAL | 9.8 | 79.5% | Apr 30, 2020 | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access... |
| CVE-2020-5872 | HIGH | 7.5 | 1.3% | Apr 30, 2020 | On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS traffic with hardwar... |
| CVE-2020-5871 | HIGH | 7.5 | 1.0% | Apr 30, 2020 | On BIG-IP 14.1.0-14.1.2.3, undisclosed requests can lead to a denial of service (DoS) when sent to BIG-IP HTTP/2 virtual... |
| CVE-2020-11015 | CRITICAL | 9.1 | 0.7% | Apr 30, 2020 | A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC add... |
| CVE-2020-1752 | HIGH | 7 | 0.5% | Apr 30, 2020 | A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was ca... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now