2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4070 | MEDIUM | 5.4 | 0.5% | Jun 22, 2020 | In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A... |
| CVE-2020-4060 | MEDIUM | 5 | 0.9% | Jun 22, 2020 | In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug i... |
| CVE-2020-13888 | MEDIUM | 5.4 | 0.5% | Jun 22, 2020 | Kordil EDMS through 2.2.60rc3 allows stored XSS in users_edit.php, users_management_edit.php, and user_management.php. |
| CVE-2020-14202 | MEDIUM | 6.1 | 0.7% | Jun 22, 2020 | WebFOCUS Business Intelligence 8.0 (SP6) was prone to XSS via arbitrary URL parameters. |
| CVE-2020-7262 | MEDIUM | 5.5 | 0.7% | Jun 22, 2020 | Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view... |
| CVE-2020-14962 | MEDIUM | 5.4 | 0.9% | Jun 22, 2020 | Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inj... |
| CVE-2020-14961 | MEDIUM | 5.3 | 0.9% | Jun 22, 2020 | Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value. |
| CVE-2020-14959 | MEDIUM | 5.4 | 0.9% | Jun 22, 2020 | Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject a... |
| CVE-2020-14958 | MEDIUM | 6.5 | 0.9% | Jun 21, 2020 | In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check. |
| CVE-2020-14954 | MEDIUM | 5.9 | 2.3% | Jun 21, 2020 | Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When... |
| CVE-2020-13264 | MEDIUM | 5.3 | 1.1% | Jun 19, 2020 | Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view... |
| CVE-2020-13276 | MEDIUM | 4.3 | 0.7% | Jun 19, 2020 | User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/E... |
| CVE-2020-13265 | MEDIUM | 5.3 | 0.7% | Jun 19, 2020 | User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification |
| CVE-2020-13262 | MEDIUM | 6.1 | 0.9% | Jun 19, 2020 | Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially craft... |
| CVE-2020-10750 | MEDIUM | 5.5 | 0.4% | Jun 19, 2020 | Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when t... |
| CVE-2020-9495 | MEDIUM | 5.3 | 8.0% | Jun 19, 2020 | Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute... |
| CVE-2020-8167 | MEDIUM | 6.5 | 1.5% | Jun 19, 2020 | A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong d... |
| CVE-2020-13277 | MEDIUM | 6.5 | 1.8% | Jun 19, 2020 | An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later... |
| CVE-2020-14927 | MEDIUM | 4.8 | 0.5% | Jun 19, 2020 | Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen. |
| CVE-2020-14926 | MEDIUM | 5.4 | 0.6% | Jun 19, 2020 | CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page. |
| CVE-2020-14475 | MEDIUM | 6.1 | 0.8% | Jun 19, 2020 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web ... |
| CVE-2020-13961 | MEDIUM | 6.5 | 1.7% | Jun 19, 2020 | Strapi before 3.0.2 could allow a remote authenticated attacker to bypass security restrictions because templates are st... |
| CVE-2020-4297 | MEDIUM | 5.4 | 0.6% | Jun 19, 2020 | IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi... |
| CVE-2020-4295 | MEDIUM | 5.4 | 0.6% | Jun 19, 2020 | IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi... |
| CVE-2020-4281 | MEDIUM | 5.4 | 0.6% | Jun 19, 2020 | IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now