2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14194 | MEDIUM | 5.4 | 0.7% | Aug 21, 2020 | Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link. |
| CVE-2020-12759 | MEDIUM | 6.1 | 0.7% | Aug 21, 2020 | Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook. |
| CVE-2020-12619 | MEDIUM | 5.9 | 0.4% | Aug 20, 2020 | MailMate before 1.11 automatically imported S/MIME certificates and thereby silently replaced existing ones. This allowe... |
| CVE-2020-12618 | MEDIUM | 4.8 | 0.3% | Aug 20, 2020 | eM Client before 7.2.33412.0 automatically imported S/MIME certificates and thereby silently replaced existing ones. Thi... |
| CVE-2020-4687 | MEDIUM | 4.3 | 1.0% | Aug 20, 2020 | IBM Content Navigator 3.0.7 and 3.0.8 could allow an authenticated user to view cached content of another user that they... |
| CVE-2020-16280 | MEDIUM | 5.5 | 0.3% | Aug 20, 2020 | Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several ex... |
| CVE-2020-15634 | MEDIUM | 6.3 | 1.4% | Aug 20, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670... |
| CVE-2020-15532 | MEDIUM | 6.5 | 1.2% | Aug 20, 2020 | Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denia... |
| CVE-2020-15119 | MEDIUM | 5.4 | 0.5% | Aug 20, 2020 | In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerously... |
| CVE-2020-13825 | MEDIUM | 6.1 | 0.8% | Aug 20, 2020 | A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HT... |
| CVE-2020-23574 | MEDIUM | 6.5 | 0.9% | Aug 19, 2020 | When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uplo... |
| CVE-2020-9712 | MEDIUM | 5.5 | 3.4% | Aug 19, 2020 | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3... |
| CVE-2020-9703 | MEDIUM | 5.5 | 2.4% | Aug 19, 2020 | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3... |
| CVE-2020-9702 | MEDIUM | 5.5 | 2.4% | Aug 19, 2020 | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3... |
| CVE-2020-9697 | MEDIUM | 5.5 | 3.1% | Aug 19, 2020 | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3... |
| CVE-2020-9696 | MEDIUM | 5.5 | 2.5% | Aug 19, 2020 | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3... |
| CVE-2020-4653 | MEDIUM | 6.1 | 0.7% | Aug 19, 2020 | IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By ... |
| CVE-2020-4648 | MEDIUM | 6.5 | 0.9% | Aug 19, 2020 | A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified ... |
| CVE-2020-4381 | MEDIUM | 6.5 | 1.0% | Aug 19, 2020 | IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denia... |
| CVE-2020-15926 | MEDIUM | 6.1 | 2.8% | Aug 18, 2020 | Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct ... |
| CVE-2020-9415 | MEDIUM | 6.5 | 0.8% | Aug 18, 2020 | The TIBCO Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtual... |
| CVE-2020-7019 | MEDIUM | 6.5 | 1.2% | Aug 18, 2020 | In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Le... |
| CVE-2020-14333 | MEDIUM | 6.1 | 0.8% | Aug 18, 2020 | A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable par... |
| CVE-2020-13183 | MEDIUM | 6.1 | 0.6% | Aug 17, 2020 | Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over ... |
| CVE-2020-12480 | MEDIUM | 6.5 | 0.5% | Aug 17, 2020 | In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now