2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-9523 | HIGH | 8.8 | 0.9% | Apr 17, 2020 | Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting ... |
| CVE-2020-4277 | HIGH | 7.5 | 1.4% | Apr 17, 2020 | IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an att... |
| CVE-2020-11875 | HIGH | 7.8 | 0.2% | Apr 17, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK ke... |
| CVE-2020-11874 | HIGH | 7.5 | 0.4% | Apr 17, 2020 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory ... |
| CVE-2020-11873 | CRITICAL | 9.8 | 0.4% | Apr 17, 2020 | An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer ove... |
| CVE-2020-11793 | HIGH | 8.8 | 2.8% | Apr 17, 2020 | A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allow... |
| CVE-2020-10947 | HIGH | 8.8 | 2.0% | Apr 17, 2020 | Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation. |
| CVE-2020-10813 | HIGH | 7.5 | 1.4% | Apr 17, 2020 | A buffer overflow vulnerability in FTPDMIN 0.96 allows attackers to crash the server via a crafted packet. |
| CVE-2020-10377 | CRITICAL | 9.8 | 0.5% | Apr 17, 2020 | A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated att... |
| CVE-2020-10211 | CRITICAL | 9.8 | 3.0% | Apr 17, 2020 | A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthent... |
| CVE-2020-11872 | HIGH | 7.5 | 0.7% | Apr 17, 2020 | The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests bef... |
| CVE-2020-11868 | HIGH | 7.5 | 2.1% | Apr 17, 2020 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronizatio... |
| CVE-2020-5294 | MEDIUM | 5.4 | 0.7% | Apr 16, 2020 | PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is ... |
| CVE-2020-5273 | MEDIUM | 5.4 | 0.7% | Apr 16, 2020 | In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fix... |
| CVE-2020-5266 | MEDIUM | 5.4 | 0.6% | Apr 16, 2020 | In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list blo... |
| CVE-2020-7486 | HIGH | 7.5 | 1.6% | Apr 16, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in... |
| CVE-2020-7485 | CRITICAL | 9.8 | 1.8% | Apr 16, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier c... |
| CVE-2020-7484 | HIGH | 7.5 | 1.3% | Apr 16, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of servi... |
| CVE-2020-7483 | HIGH | 7.5 | 0.9% | Apr 16, 2020 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the '... |
| CVE-2020-7224 | CRITICAL | 9.8 | 2.3% | Apr 16, 2020 | The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered... |
| CVE-2020-7114 | CRITICAL | 9.8 | 1.1% | Apr 16, 2020 | A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, ... |
| CVE-2020-7113 | MEDIUM | 4.9 | 0.9% | Apr 16, 2020 | A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to inte... |
| CVE-2020-7111 | HIGH | 7.2 | 1.9% | Apr 16, 2020 | A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Co... |
| CVE-2020-7110 | MEDIUM | 4.8 | 0.6% | Apr 16, 2020 | ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administr... |
| CVE-2020-2180 | HIGH | 8.8 | 2.3% | Apr 16, 2020 | Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now