2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-13352MEDIUM5.3Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to pu...
CVE-2020-11860MEDIUM6.1Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vul...
CVE-2020-26225MEDIUM6.1In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web bro...
CVE-2020-4763MEDIUM4.3IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secure attribute on autho...
CVE-2020-4705MEDIUM4.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to cross-...
CVE-2020-4692MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenti...
CVE-2020-4672MEDIUM5.4IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2020-4671MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sens...
CVE-2020-4665MEDIUM4.3IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on autho...
CVE-2020-4566MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially high...
CVE-2020-4475MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote at...
CVE-2020-27991MEDIUM5.4Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
CVE-2020-27990MEDIUM5.4Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
CVE-2020-27989MEDIUM5.4Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
CVE-2020-27988MEDIUM5.4Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
CVE-2020-27627MEDIUM6.1JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
CVE-2020-27622MEDIUM5.3In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
CVE-2020-26129MEDIUM6.5In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
CVE-2020-13773MEDIUM5.4Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_spli...
CVE-2020-13772MEDIUM5.3In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about t...
CVE-2020-27629MEDIUM5.3In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there a...
CVE-2020-27628MEDIUM4.3In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
CVE-2020-27626MEDIUM5.3JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
CVE-2020-27625MEDIUM5.3In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
CVE-2020-27624MEDIUM5.3JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now