2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13352 | MEDIUM | 5.3 | 1.2% | Nov 17, 2020 | Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to pu... |
| CVE-2020-11860 | MEDIUM | 6.1 | 0.6% | Nov 17, 2020 | Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vul... |
| CVE-2020-26225 | MEDIUM | 6.1 | 0.9% | Nov 16, 2020 | In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web bro... |
| CVE-2020-4763 | MEDIUM | 4.3 | 1.0% | Nov 16, 2020 | IBM Sterling File Gateway 6.0.0.0 through 6.0.3.2 and 2.2.0.0 through 2.2.6.5 does not set the secure attribute on autho... |
| CVE-2020-4705 | MEDIUM | 4.8 | 0.5% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to cross-... |
| CVE-2020-4692 | MEDIUM | 6.5 | 0.9% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenti... |
| CVE-2020-4672 | MEDIUM | 5.4 | 0.6% | Nov 16, 2020 | IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2020-4671 | MEDIUM | 6.5 | 1.0% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sens... |
| CVE-2020-4665 | MEDIUM | 4.3 | 1.0% | Nov 16, 2020 | IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on autho... |
| CVE-2020-4566 | MEDIUM | 6.5 | 1.0% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially high... |
| CVE-2020-4475 | MEDIUM | 6.5 | 1.1% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote at... |
| CVE-2020-27991 | MEDIUM | 5.4 | 21.7% | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field). |
| CVE-2020-27990 | MEDIUM | 5.4 | 21.7% | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent). |
| CVE-2020-27989 | MEDIUM | 5.4 | 21.7% | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard). |
| CVE-2020-27988 | MEDIUM | 5.4 | 87.2% | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field). |
| CVE-2020-27627 | MEDIUM | 6.1 | 0.7% | Nov 16, 2020 | JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection. |
| CVE-2020-27622 | MEDIUM | 5.3 | 1.3% | Nov 16, 2020 | In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version. |
| CVE-2020-26129 | MEDIUM | 6.5 | 0.8% | Nov 16, 2020 | In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible. |
| CVE-2020-13773 | MEDIUM | 5.4 | 1.3% | Nov 16, 2020 | Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_spli... |
| CVE-2020-13772 | MEDIUM | 5.3 | 2.3% | Nov 16, 2020 | In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about t... |
| CVE-2020-27629 | MEDIUM | 5.3 | 0.9% | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there a... |
| CVE-2020-27628 | MEDIUM | 4.3 | 0.7% | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records. |
| CVE-2020-27626 | MEDIUM | 5.3 | 1.3% | Nov 16, 2020 | JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF. |
| CVE-2020-27625 | MEDIUM | 5.3 | 1.4% | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues. |
| CVE-2020-27624 | MEDIUM | 5.3 | 1.4% | Nov 16, 2020 | JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now