2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24861 | MEDIUM | 5.4 | 0.9% | Oct 1, 2020 | GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is execu... |
| CVE-2020-24860 | MEDIUM | 5.4 | 1.1% | Oct 1, 2020 | CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persisten... |
| CVE-2020-25830 | MEDIUM | 4.8 | 1.7% | Sep 30, 2020 | An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inje... |
| CVE-2020-25781 | MEDIUM | 4.3 | 0.9% | Sep 30, 2020 | An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes... |
| CVE-2020-25288 | MEDIUM | 4.8 | 1.5% | Sep 30, 2020 | An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafte... |
| CVE-2020-13336 | MEDIUM | 4.8 | 0.5% | Sep 30, 2020 | An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored X... |
| CVE-2020-12869 | MEDIUM | 5.4 | 0.6% | Sep 30, 2020 | RainbowFish PacsOne Server 6.8.4 allows XSS. |
| CVE-2020-25816 | MEDIUM | 6.8 | 1.0% | Sep 30, 2020 | HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their T... |
| CVE-2020-25626 | MEDIUM | 6.1 | 1.3% | Sep 30, 2020 | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer... |
| CVE-2020-8256 | MEDIUM | 4.9 | 3.4% | Sep 30, 2020 | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain ... |
| CVE-2020-8238 | MEDIUM | 6.1 | 1.7% | Sep 30, 2020 | A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could ... |
| CVE-2020-26137 | MEDIUM | 6.5 | 2.2% | Sep 30, 2020 | urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserti... |
| CVE-2020-26043 | MEDIUM | 6.1 | 0.7% | Sep 30, 2020 | An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php |
| CVE-2020-25761 | MEDIUM | 6.1 | 1.8% | Sep 30, 2020 | Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on ... |
| CVE-2020-24721 | MEDIUM | 5.7 | 0.3% | Sep 30, 2020 | An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in CO... |
| CVE-2020-24570 | MEDIUM | 6.5 | 0.5% | Sep 30, 2020 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resu... |
| CVE-2020-24569 | MEDIUM | 4.3 | 0.7% | Sep 30, 2020 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection i... |
| CVE-2020-22842 | MEDIUM | 5.4 | 0.5% | Sep 30, 2020 | CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/mod... |
| CVE-2020-22481 | MEDIUM | 6.1 | 0.6% | Sep 30, 2020 | An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered ... |
| CVE-2020-21244 | MEDIUM | 4.9 | 1.0% | Sep 30, 2020 | An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via... |
| CVE-2020-19676 | MEDIUM | 5.3 | 1.4% | Sep 30, 2020 | Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details in... |
| CVE-2020-19670 | MEDIUM | 4.9 | 0.9% | Sep 30, 2020 | In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any... |
| CVE-2020-15595 | MEDIUM | 4.3 | 2.2% | Sep 30, 2020 | An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to ... |
| CVE-2020-15594 | MEDIUM | 4.3 | 1.8% | Sep 30, 2020 | An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration fe... |
| CVE-2020-13953 | MEDIUM | 5.3 | 2.7% | Sep 30, 2020 | In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now