2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-27010 | MEDIUM | 4.8 | 0.7% | Dec 17, 2020 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow a... |
| CVE-2020-4845 | MEDIUM | 5.4 | 0.6% | Dec 17, 2020 | IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2020-15293 | MEDIUM | 5.5 | 0.3% | Dec 17, 2020 | Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to ins... |
| CVE-2020-15292 | MEDIUM | 5.5 | 0.3% | Dec 17, 2020 | Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, Int... |
| CVE-2020-35453 | MEDIUM | 5.3 | 0.8% | Dec 17, 2020 | HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibl... |
| CVE-2020-35177 | MEDIUM | 5.3 | 1.3% | Dec 17, 2020 | HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in... |
| CVE-2020-35123 | MEDIUM | 6.5 | 1.5% | Dec 17, 2020 | In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in ... |
| CVE-2020-29436 | MEDIUM | 6.5 | 1.4% | Dec 17, 2020 | Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain ... |
| CVE-2020-4908 | MEDIUM | 5.3 | 1.1% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release in... |
| CVE-2020-4907 | MEDIUM | 5.3 | 1.3% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain se... |
| CVE-2020-4905 | MEDIUM | 5.9 | 1.3% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain s... |
| CVE-2020-4904 | MEDIUM | 6.5 | 0.5% | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forger... |
| CVE-2020-4658 | MEDIUM | 6.1 | 0.7% | Dec 16, 2020 | IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2020-4657 | MEDIUM | 6.1 | 0.7% | Dec 16, 2020 | IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnera... |
| CVE-2020-28930 | MEDIUM | 5.4 | 0.6% | Dec 16, 2020 | A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON... |
| CVE-2020-5359 | MEDIUM | 5.8 | 1.1% | Dec 16, 2020 | Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An una... |
| CVE-2020-26198 | MEDIUM | 6.1 | 1.0% | Dec 16, 2020 | Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in th... |
| CVE-2020-14248 | MEDIUM | 5.3 | 0.7% | Dec 16, 2020 | BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause ... |
| CVE-2020-29362 | MEDIUM | 5.3 | 2.3% | Dec 16, 2020 | An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC ... |
| CVE-2020-25619 | MEDIUM | 4.4 | 0.4% | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channe... |
| CVE-2020-26273 | MEDIUM | 5.2 | 0.9% | Dec 16, 2020 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before versio... |
| CVE-2020-26259 | MEDIUM | 6.8 | 81.0% | Dec 16, 2020 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to... |
| CVE-2020-35416 | MEDIUM | 6.1 | 2.7% | Dec 15, 2020 | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admi... |
| CVE-2020-23957 | MEDIUM | 6.1 | 0.7% | Dec 15, 2020 | Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by... |
| CVE-2020-14302 | MEDIUM | 4.9 | 1.0% | Dec 15, 2020 | A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirec... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now