2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-14470MEDIUM6.5In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that l...
CVE-2020-14460MEDIUM6.5An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAu...
CVE-2020-14457MEDIUM5.3An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the upd...
CVE-2020-14455MEDIUM6.5An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, a...
CVE-2020-14454MEDIUM6.1An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application ...
CVE-2020-14452MEDIUM5.3An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-001...
CVE-2020-14462MEDIUM5.4CALDERA 2.7.0 allows XSS via the Operation Name box.
CVE-2020-14446MEDIUM6.1An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redire...
CVE-2020-14445MEDIUM5.4An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Refl...
CVE-2020-14444MEDIUM5.4An issue was discovered in WSO2 Identity Server through 5.9.0 and WSO2 IS as Key Manager through 5.9.0. A potential Refl...
CVE-2020-13882MEDIUM4.2CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log ...
CVE-2020-14434MEDIUM6.8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.15.25...
CVE-2020-14433MEDIUM6.8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.15.25...
CVE-2020-1835MEDIUM6.5HUAWEI Mate 30 with versions earlier than 10.1.0.126(C00E125R5P3) have an information disclosure vulnerability. A logic ...
CVE-2020-1834MEDIUM4.6HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C...
CVE-2020-14423MEDIUM5.3Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictab...
CVE-2020-14422MEDIUM5.9Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes,...
CVE-2020-10782MEDIUM6.5An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and oth...
CVE-2020-14416MEDIUM4.2In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline cou...
CVE-2020-3368MEDIUM5.8A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)...
CVE-2020-3364MEDIUM5.3A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Ci...
CVE-2020-3362MEDIUM4.7A vulnerability in the CLI of Cisco Network Services Orchestrator (NSO) could allow an authenticated, local attacker to ...
CVE-2020-3360MEDIUM5.3A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated,...
CVE-2020-3356MEDIUM6.1A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2020-3355MEDIUM4.8A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authent...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now