2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-15651 | MEDIUM | 4.3 | 0.6% | Aug 10, 2020 | A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI f... |
| CVE-2020-15650 | MEDIUM | 5.5 | 0.6% | Aug 10, 2020 | Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite F... |
| CVE-2020-15649 | MEDIUM | 5.5 | 0.7% | Aug 10, 2020 | Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choo... |
| CVE-2020-15648 | MEDIUM | 6.5 | 1.1% | Aug 10, 2020 | Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-O... |
| CVE-2020-17476 | MEDIUM | 6.1 | 0.7% | Aug 10, 2020 | Mibew Messenger before 3.2.7 allows XSS via a crafted user name. |
| CVE-2020-9526 | MEDIUM | 5.9 | 0.6% | Aug 10, 2020 | CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure fla... |
| CVE-2020-8229 | MEDIUM | 5.5 | 0.5% | Aug 10, 2020 | A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system... |
| CVE-2020-13294 | MEDIUM | 5.4 | 1.2% | Aug 10, 2020 | In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application... |
| CVE-2020-4541 | MEDIUM | 6.1 | 0.7% | Aug 10, 2020 | IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2020-4539 | MEDIUM | 6.1 | 0.7% | Aug 10, 2020 | IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2020-4533 | MEDIUM | 6.1 | 0.7% | Aug 10, 2020 | IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2020-12779 | MEDIUM | 5.4 | 0.6% | Aug 10, 2020 | Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with maliciou... |
| CVE-2020-12778 | MEDIUM | 6.1 | 0.8% | Aug 10, 2020 | Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack. |
| CVE-2020-17451 | MEDIUM | 4.8 | 0.6% | Aug 9, 2020 | flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title,... |
| CVE-2020-16248 | MEDIUM | 5.8 | 2.7% | Aug 9, 2020 | Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this mi... |
| CVE-2020-15831 | MEDIUM | 6.1 | 0.6% | Aug 8, 2020 | JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI. |
| CVE-2020-15830 | MEDIUM | 6.1 | 0.8% | Aug 8, 2020 | JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI. |
| CVE-2020-15829 | MEDIUM | 5.3 | 0.9% | Aug 8, 2020 | In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs. |
| CVE-2020-15828 | MEDIUM | 6.5 | 1.1% | Aug 8, 2020 | In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissio... |
| CVE-2020-15826 | MEDIUM | 4.3 | 0.5% | Aug 8, 2020 | In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have. |
| CVE-2020-15821 | MEDIUM | 6.5 | 0.9% | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft. |
| CVE-2020-15820 | MEDIUM | 5.3 | 1.4% | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence. |
| CVE-2020-15819 | MEDIUM | 5.3 | 1.4% | Aug 8, 2020 | JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports. |
| CVE-2020-15818 | MEDIUM | 5.3 | 1.4% | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence. |
| CVE-2020-15065 | MEDIUM | 6.5 | 0.5% | Aug 7, 2020 | DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-s... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now