2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11464 | MEDIUM | 4.3 | 1.2% | Apr 1, 2020 | An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privil... |
| CVE-2020-11463 | HIGH | 7.5 | 1.8% | Apr 1, 2020 | An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user'... |
| CVE-2020-10948 | CRITICAL | 9.8 | 6.7% | Apr 1, 2020 | Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution v... |
| CVE-2020-10598 | MEDIUM | 6.1 | 0.3% | Apr 1, 2020 | In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment es... |
| CVE-2020-5290 | MEDIUM | 6.5 | 0.8% | Apr 1, 2020 | In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` has... |
| CVE-2020-1934 | MEDIUM | 5.3 | 52.0% | Apr 1, 2020 | In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP serve... |
| CVE-2020-3850 | CRITICAL | 9.8 | 3.2% | Apr 1, 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A... |
| CVE-2020-3849 | CRITICAL | 9.8 | 2.2% | Apr 1, 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A... |
| CVE-2020-3848 | CRITICAL | 9.8 | 2.2% | Apr 1, 2020 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A... |
| CVE-2020-3847 | CRITICAL | 9.8 | 2.2% | Apr 1, 2020 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A rem... |
| CVE-2020-1949 | MEDIUM | 6.1 | 2.0% | Apr 1, 2020 | Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elem... |
| CVE-2020-1943 | MEDIUM | 6.1 | 97.3% | Apr 1, 2020 | Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07. |
| CVE-2020-10204 | HIGH | 7.2 | 24.3% | Apr 1, 2020 | Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution. |
| CVE-2020-10203 | MEDIUM | 4.8 | 0.9% | Apr 1, 2020 | Sonatype Nexus Repository before 3.21.2 allows XSS. |
| CVE-2020-10199 | HIGH | 8.8 | 99.1% | Apr 1, 2020 | Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). |
| CVE-2020-9785 | HIGH | 7.8 | 1.3% | Apr 1, 2020 | Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.4 and iPa... |
| CVE-2020-9784 | MEDIUM | 4.3 | 0.8% | Apr 1, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use a... |
| CVE-2020-9783 | HIGH | 8.8 | 1.3% | Apr 1, 2020 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, t... |
| CVE-2020-9781 | MEDIUM | 5.3 | 0.8% | Apr 1, 2020 | The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPa... |
| CVE-2020-9780 | LOW | 3.3 | 0.3% | Apr 1, 2020 | The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPa... |
| CVE-2020-9777 | MEDIUM | 5.3 | 0.8% | Apr 1, 2020 | An issue existed in the selection of video file by Mail. The issue was fixed by selecting the latest version of a video.... |
| CVE-2020-9776 | LOW | 3.3 | 0.6% | Apr 1, 2020 | This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A malicious application ... |
| CVE-2020-9775 | MEDIUM | 5.3 | 0.9% | Apr 1, 2020 | An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved stat... |
| CVE-2020-9773 | LOW | 3.3 | 0.6% | Apr 1, 2020 | The issue was addressed with improved handling of icon caches. This issue is fixed in iOS 14.0 and iPadOS 14.0. A malici... |
| CVE-2020-9770 | MEDIUM | 6.5 | 1.2% | Apr 1, 2020 | A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now