2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2100 | MEDIUM | 5.8 | 3.4% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service at... |
| CVE-2020-2099 | HIGH | 8.6 | 1.0% | Jan 29, 2020 | Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent ... |
| CVE-2020-7965 | HIGH | 8.8 | 0.5% | Jan 29, 2020 | flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receivin... |
| CVE-2020-8428 | HIGH | 7.1 | 0.7% | Jan 29, 2020 | fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a... |
| CVE-2020-8426 | MEDIUM | 5.4 | 1.3% | Jan 28, 2020 | The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info ... |
| CVE-2020-8425 | MEDIUM | 6.5 | 1.2% | Jan 28, 2020 | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php. |
| CVE-2020-8424 | HIGH | 8.8 | 1.5% | Jan 28, 2020 | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php... |
| CVE-2020-5227 | HIGH | 7.5 | 1.6% | Jan 28, 2020 | Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supp... |
| CVE-2020-5215 | HIGH | 7.5 | 0.6% | Jan 28, 2020 | In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation... |
| CVE-2020-8421 | MEDIUM | 6.1 | 1.0% | Jan 28, 2020 | An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs. |
| CVE-2020-8420 | HIGH | 8.8 | 0.8% | Jan 28, 2020 | An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates cause... |
| CVE-2020-8419 | HIGH | 8.8 | 0.5% | Jan 28, 2020 | An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause ... |
| CVE-2020-8417 | HIGH | 8.8 | 10.4% | Jan 28, 2020 | The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import me... |
| CVE-2020-8315 | MEDIUM | 5.5 | 1.3% | Jan 28, 2020 | In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launc... |
| CVE-2020-5211 | CRITICAL | 9.8 | 1.1% | Jan 28, 2020 | In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a... |
| CVE-2020-4207 | CRITICAL | 9.8 | 4.5% | Jan 28, 2020 | IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by impr... |
| CVE-2020-8112 | HIGH | 8.8 | 3.6% | Jan 28, 2020 | opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in th... |
| CVE-2020-5214 | CRITICAL | 9.8 | 1.1% | Jan 28, 2020 | In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash... |
| CVE-2020-5213 | CRITICAL | 9.8 | 1.1% | Jan 28, 2020 | In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow result... |
| CVE-2020-5212 | CRITICAL | 9.8 | 1.1% | Jan 28, 2020 | In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow... |
| CVE-2020-5210 | HIGH | 7.8 | 0.8% | Jan 28, 2020 | In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a cr... |
| CVE-2020-5209 | HIGH | 7.8 | 0.8% | Jan 28, 2020 | In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or re... |
| CVE-2020-8086 | CRITICAL | 9.8 | 1.6% | Jan 28, 2020 | The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP addre... |
| CVE-2020-1940 | HIGH | 7.5 | 4.5% | Jan 28, 2020 | The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 a... |
| CVE-2020-7934 | MEDIUM | 5.4 | 4.5% | Jan 28, 2020 | In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now