2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10006 | MEDIUM | 5.5 | 0.9% | Dec 8, 2020 | This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.0.1. A malicious applicatio... |
| CVE-2020-10002 | MEDIUM | 5.5 | 0.4% | Dec 8, 2020 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iO... |
| CVE-2020-1971 | MEDIUM | 5.9 | 7.0% | Dec 8, 2020 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known... |
| CVE-2020-25955 | MEDIUM | 5.4 | 0.9% | Dec 8, 2020 | SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS)... |
| CVE-2020-29539 | MEDIUM | 5.4 | 0.7% | Dec 8, 2020 | A Cross-Site Scripting (XSS) issue in WebUI Translation in Systran Pure Neural Server before 9.7.0 allows a threat actor... |
| CVE-2020-26253 | MEDIUM | 5.9 | 0.6% | Dec 8, 2020 | Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulne... |
| CVE-2020-27822 | MEDIUM | 5.9 | 1.1% | Dec 8, 2020 | A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final.... |
| CVE-2020-25677 | MEDIUM | 5.5 | 0.2% | Dec 8, 2020 | A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissi... |
| CVE-2020-25631 | MEDIUM | 6.1 | 0.9% | Dec 8, 2020 | A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScr... |
| CVE-2020-25628 | MEDIUM | 6.1 | 1.0% | Dec 8, 2020 | The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 ... |
| CVE-2020-8566 | MEDIUM | 5.5 | 0.5% | Dec 7, 2020 | In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets... |
| CVE-2020-8565 | MEDIUM | 5.5 | 0.5% | Dec 7, 2020 | In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. ... |
| CVE-2020-8564 | MEDIUM | 5.5 | 0.5% | Dec 7, 2020 | In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the... |
| CVE-2020-8563 | MEDIUM | 5.5 | 0.5% | Dec 7, 2020 | In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credenti... |
| CVE-2020-28935 | MEDIUM | 5.5 | 0.5% | Dec 7, 2020 | NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a... |
| CVE-2020-17521 | MEDIUM | 5.5 | 1.1% | Dec 7, 2020 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's impleme... |
| CVE-2020-13945 | MEDIUM | 6.5 | 73.0% | Dec 7, 2020 | In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the ... |
| CVE-2020-26513 | MEDIUM | 5.5 | 0.9% | Dec 7, 2020 | An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM ... |
| CVE-2020-28727 | MEDIUM | 6.1 | 0.9% | Dec 7, 2020 | Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChoose... |
| CVE-2020-29572 | MEDIUM | 6.1 | 0.8% | Dec 6, 2020 | app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment fi... |
| CVE-2020-25449 | MEDIUM | 4.8 | 1.1% | Dec 4, 2020 | Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column. |
| CVE-2020-27409 | MEDIUM | 6.1 | 1.0% | Dec 4, 2020 | OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via... |
| CVE-2020-27770 | MEDIUM | 5.5 | 1.1% | Dec 4, 2020 | Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(),... |
| CVE-2020-29565 | MEDIUM | 6.1 | 1.4% | Dec 4, 2020 | An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and... |
| CVE-2020-29562 | MEDIUM | 4.8 | 1.5% | Dec 4, 2020 | The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irrev... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now