2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10006MEDIUM5.5This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.0.1. A malicious applicatio...
CVE-2020-10002MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iO...
CVE-2020-1971MEDIUM5.9The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known...
CVE-2020-25955MEDIUM5.4SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS)...
CVE-2020-29539MEDIUM5.4A Cross-Site Scripting (XSS) issue in WebUI Translation in Systran Pure Neural Server before 9.7.0 allows a threat actor...
CVE-2020-26253MEDIUM5.9Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulne...
CVE-2020-27822MEDIUM5.9A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final....
CVE-2020-25677MEDIUM5.5A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissi...
CVE-2020-25631MEDIUM6.1A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScr...
CVE-2020-25628MEDIUM6.1The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 ...
CVE-2020-8566MEDIUM5.5In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets...
CVE-2020-8565MEDIUM5.5In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. ...
CVE-2020-8564MEDIUM5.5In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the...
CVE-2020-8563MEDIUM5.5In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credenti...
CVE-2020-28935MEDIUM5.5NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a...
CVE-2020-17521MEDIUM5.5Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's impleme...
CVE-2020-13945MEDIUM6.5In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the ...
CVE-2020-26513MEDIUM5.5An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM ...
CVE-2020-28727MEDIUM6.1Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChoose...
CVE-2020-29572MEDIUM6.1app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment fi...
CVE-2020-25449MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column.
CVE-2020-27409MEDIUM6.1OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via...
CVE-2020-27770MEDIUM5.5Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(),...
CVE-2020-29565MEDIUM6.1An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and...
CVE-2020-29562MEDIUM4.8The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irrev...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now