2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29536 | MEDIUM | 4.3 | 0.5% | Jan 29, 2021 | Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker w... |
| CVE-2020-29535 | MEDIUM | 5.4 | 0.8% | Jan 29, 2021 | Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could p... |
| CVE-2020-29005 | HIGH | 7.5 | 0.7% | Jan 29, 2021 | The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential ... |
| CVE-2020-29004 | HIGH | 8.8 | 0.7% | Jan 29, 2021 | The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore ... |
| CVE-2020-28406 | MEDIUM | 6.5 | 1.3% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-28405 | HIGH | 8.8 | 1.6% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-28404 | MEDIUM | 6.5 | 1.3% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-28403 | HIGH | 8.8 | 0.7% | Jan 29, 2021 | A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an... |
| CVE-2020-28402 | HIGH | 8.8 | 1.4% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-28401 | MEDIUM | 6.5 | 1.3% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-8585 | MEDIUM | 5.5 | 0.4% | Jan 28, 2021 | OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorize... |
| CVE-2020-36115 | MEDIUM | 5.4 | 0.6% | Jan 28, 2021 | Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf ... |
| CVE-2020-35754 | HIGH | 7.2 | 10.5% | Jan 28, 2021 | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl... |
| CVE-2020-35517 | HIGH | 8.2 | 0.5% | Jan 28, 2021 | A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a... |
| CVE-2020-1725 | MEDIUM | 5.4 | 0.7% | Jan 28, 2021 | A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changi... |
| CVE-2020-1723 | MEDIUM | 6.1 | 1.0% | Jan 28, 2021 | A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbi... |
| CVE-2020-26272 | MEDIUM | 6.5 | 1.8% | Jan 28, 2021 | The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions ... |
| CVE-2020-4888 | HIGH | 8.8 | 62.0% | Jan 28, 2021 | IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary com... |
| CVE-2020-4682 | CRITICAL | 9.8 | 7.7% | Jan 28, 2021 | IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, ca... |
| CVE-2020-13569 | HIGH | 8.8 | 3.0% | Jan 28, 2021 | A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0... |
| CVE-2020-5626 | HIGH | 8.8 | 2.2% | Jan 28, 2021 | Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbi... |
| CVE-2020-35124 | CRITICAL | 9.6 | 2.4% | Jan 28, 2021 | A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inj... |
| CVE-2020-25785 | CRITICAL | 9.8 | 1.5% | Jan 28, 2021 | An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.... |
| CVE-2020-25784 | CRITICAL | 9.8 | 1.7% | Jan 28, 2021 | An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.... |
| CVE-2020-25783 | CRITICAL | 9.8 | 1.7% | Jan 28, 2021 | An issue was discovered on Accfly Wireless Security IR Camera System 720P with software versions v3.10.73 through v4.15.... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now