2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35475 | HIGH | 7.5 | 1.6% | Dec 18, 2020 | In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS ... |
| CVE-2020-27640 | HIGH | 8.1 | 0.5% | Dec 18, 2020 | The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthentica... |
| CVE-2020-27639 | HIGH | 8.1 | 0.5% | Dec 18, 2020 | The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an un... |
| CVE-2020-27154 | HIGH | 8.8 | 1.0% | Dec 18, 2020 | The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allo... |
| CVE-2020-25608 | HIGH | 7.2 | 0.9% | Dec 18, 2020 | The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input val... |
| CVE-2020-7838 | HIGH | 8.8 | 1.2% | Dec 18, 2020 | A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An at... |
| CVE-2020-28052 | HIGH | 8.1 | 7.1% | Dec 18, 2020 | An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility me... |
| CVE-2020-14232 | HIGH | 8.8 | 1.3% | Dec 18, 2020 | A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attac... |
| CVE-2020-8464 | HIGH | 7.5 | 6.3% | Dec 17, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests... |
| CVE-2020-8463 | HIGH | 7.5 | 5.9% | Dec 17, 2020 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a glob... |
| CVE-2020-8461 | HIGH | 8.8 | 1.1% | Dec 17, 2020 | A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an at... |
| CVE-2020-35491 | HIGH | 8.1 | 9.5% | Dec 17, 2020 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-35490 | HIGH | 8.1 | 7.7% | Dec 17, 2020 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, rela... |
| CVE-2020-15294 | HIGH | 7 | 0.3% | Dec 17, 2020 | Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results ... |
| CVE-2020-29652 | HIGH | 7.5 | 3.2% | Dec 17, 2020 | A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go all... |
| CVE-2020-27199 | HIGH | 7.5 | 2.9% | Dec 17, 2020 | The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application... |
| CVE-2020-25096 | HIGH | 8.8 | 1.0% | Dec 17, 2020 | LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different ro... |
| CVE-2020-25095 | HIGH | 8.8 | 1.0% | Dec 17, 2020 | LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CS... |
| CVE-2020-28931 | HIGH | 8.8 | 0.5% | Dec 16, 2020 | Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthen... |
| CVE-2020-26274 | HIGH | 8.8 | 2.7% | Dec 16, 2020 | In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fix... |
| CVE-2020-35133 | HIGH | 7.5 | 4.4% | Dec 16, 2020 | irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32... |
| CVE-2020-7837 | HIGH | 8.8 | 0.7% | Dec 16, 2020 | An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportD... |
| CVE-2020-5360 | HIGH | 7.5 | 2.2% | Dec 16, 2020 | Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthent... |
| CVE-2020-29607 | HIGH | 7.2 | 33.4% | Dec 16, 2020 | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access... |
| CVE-2020-25622 | HIGH | 8.8 | 0.9% | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now