2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-17437 | HIGH | 8.2 | 2.8% | Dec 11, 2020 | An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP pack... |
| CVE-2020-13988 | HIGH | 7.5 | 3.9% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsin... |
| CVE-2020-13987 | HIGH | 7.5 | 3.2% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack compo... |
| CVE-2020-13986 | HIGH | 7.5 | 3.0% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling ... |
| CVE-2020-13985 | HIGH | 7.5 | 4.8% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack compone... |
| CVE-2020-13984 | HIGH | 7.5 | 1.7% | Dec 11, 2020 | An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processin... |
| CVE-2020-5949 | HIGH | 7.5 | 1.0% | Dec 11, 2020 | On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with a... |
| CVE-2020-27713 | HIGH | 7.5 | 1.3% | Dec 11, 2020 | In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server an... |
| CVE-2020-7791 | HIGH | 7.5 | 3.0% | Dec 11, 2020 | This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tag... |
| CVE-2020-29254 | HIGH | 8.8 | 1.5% | Dec 11, 2020 | TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacke... |
| CVE-2020-27508 | HIGH | 7.5 | 1.3% | Dec 11, 2020 | In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach th... |
| CVE-2020-4633 | HIGH | 8.8 | 2.7% | Dec 11, 2020 | IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula inject... |
| CVE-2020-7793 | HIGH | 7.5 | 3.9% | Dec 11, 2020 | The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexe... |
| CVE-2020-7792 | HIGH | 7.5 | 2.1% | Dec 11, 2020 | This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively',... |
| CVE-2020-35135 | HIGH | 8.8 | 0.9% | Dec 11, 2020 | The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF. |
| CVE-2020-27786 | HIGH | 7.8 | 1.7% | Dec 11, 2020 | A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permission... |
| CVE-2020-27828 | HIGH | 7.8 | 1.4% | Dec 11, 2020 | There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker coul... |
| CVE-2020-13530 | HIGH | 7.5 | 2.1% | Dec 11, 2020 | A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and d... |
| CVE-2020-13520 | HIGH | 7.8 | 2.0% | Dec 11, 2020 | An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary US... |
| CVE-2020-9301 | HIGH | 8.8 | 1.5% | Dec 11, 2020 | Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to versio... |
| CVE-2020-24447 | HIGH | 7 | 0.8% | Dec 11, 2020 | Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability ... |
| CVE-2020-24440 | HIGH | 7 | 0.6% | Dec 11, 2020 | Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitr... |
| CVE-2020-25191 | HIGH | 7.5 | 1.1% | Dec 11, 2020 | Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user... |
| CVE-2020-24637 | HIGH | 7.2 | 1.6% | Dec 11, 2020 | Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation... |
| CVE-2020-7560 | HIGH | 8.6 | 1.4% | Dec 11, 2020 | A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now