2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-15651MEDIUM4.3A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI f...
CVE-2020-15650MEDIUM5.5Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite F...
CVE-2020-15649MEDIUM5.5Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choo...
CVE-2020-15648MEDIUM6.5Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-O...
CVE-2020-17476MEDIUM6.1Mibew Messenger before 3.2.7 allows XSS via a crafted user name.
CVE-2020-9526MEDIUM5.9CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure fla...
CVE-2020-8229MEDIUM5.5A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system...
CVE-2020-13294MEDIUM5.4In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application...
CVE-2020-4541MEDIUM6.1IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2020-4539MEDIUM6.1IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerabili...
CVE-2020-4533MEDIUM6.1IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2020-12779MEDIUM5.4Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with maliciou...
CVE-2020-12778MEDIUM6.1Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
CVE-2020-17451MEDIUM4.8flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title,...
CVE-2020-16248MEDIUM5.8Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this mi...
CVE-2020-15831MEDIUM6.1JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
CVE-2020-15830MEDIUM6.1JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
CVE-2020-15829MEDIUM5.3In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
CVE-2020-15828MEDIUM6.5In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissio...
CVE-2020-15826MEDIUM4.3In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
CVE-2020-15821MEDIUM6.5In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
CVE-2020-15820MEDIUM5.3In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
CVE-2020-15819MEDIUM5.3JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
CVE-2020-15818MEDIUM5.3In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
CVE-2020-15065MEDIUM6.5DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-s...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now