2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13964 | MEDIUM | 6.1 | 1.0% | Jun 9, 2020 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows... |
| CVE-2020-13844 | MEDIUM | 5.5 | 0.5% | Jun 8, 2020 | Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow un... |
| CVE-2020-4041 | MEDIUM | 6.1 | 2.0% | Jun 8, 2020 | In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inj... |
| CVE-2020-4040 | MEDIUM | 4.3 | 1.8% | Jun 8, 2020 | Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be gen... |
| CVE-2020-10754 | MEDIUM | 4.3 | 1.0% | Jun 8, 2020 | It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-p... |
| CVE-2020-8954 | MEDIUM | 5.4 | 0.8% | Jun 8, 2020 | OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manip... |
| CVE-2020-13696 | MEDIUM | 4.4 | 0.4% | Jun 8, 2020 | An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient... |
| CVE-2020-12049 | MEDIUM | 5.5 | 0.6% | Jun 8, 2020 | An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file d... |
| CVE-2020-1775 | MEDIUM | 4.3 | 0.8% | Jun 8, 2020 | BCC recipients in mails sent from OTRS are visible in article detail on external interface. This issue affects OTRS: 8.0... |
| CVE-2020-12803 | MEDIUM | 6.5 | 1.7% | Jun 8, 2020 | ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be subm... |
| CVE-2020-12802 | MEDIUM | 5.3 | 1.9% | Jun 8, 2020 | LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote ... |
| CVE-2020-7676 | MEDIUM | 5.4 | 2.1% | Jun 8, 2020 | angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code in... |
| CVE-2020-13904 | MEDIUM | 5.5 | 1.3% | Jun 7, 2020 | FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavf... |
| CVE-2020-13897 | MEDIUM | 6.1 | 0.6% | Jun 7, 2020 | HESK before 3.1.10 allows reflected XSS. |
| CVE-2020-13890 | MEDIUM | 5.4 | 0.5% | Jun 6, 2020 | The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard. |
| CVE-2020-13889 | MEDIUM | 5.4 | 0.9% | Jun 6, 2020 | showAlert() in the administration panel in Bludit 3.12.0 allows XSS. |
| CVE-2020-13883 | MEDIUM | 6.7 | 0.8% | Jun 6, 2020 | In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Manage... |
| CVE-2020-13865 | MEDIUM | 5.4 | 0.8% | Jun 5, 2020 | The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author... |
| CVE-2020-13864 | MEDIUM | 5.4 | 0.8% | Jun 5, 2020 | The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can... |
| CVE-2020-11696 | MEDIUM | 6.1 | 0.7% | Jun 5, 2020 | In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (com... |
| CVE-2020-11697 | MEDIUM | 6.1 | 0.7% | Jun 5, 2020 | In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (commu... |
| CVE-2020-13870 | MEDIUM | 5.4 | 0.5% | Jun 5, 2020 | An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name. |
| CVE-2020-13869 | MEDIUM | 5.4 | 0.5% | Jun 5, 2020 | An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name. |
| CVE-2020-13868 | MEDIUM | 6.5 | 0.4% | Jun 5, 2020 | An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. |
| CVE-2020-13867 | MEDIUM | 5.5 | 0.3% | Jun 5, 2020 | Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup fil... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now