2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28482HIGH8.8This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the...
CVE-2020-28481MEDIUM4.3The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whi...
CVE-2020-28480CRITICAL9.8The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com...
CVE-2020-28479HIGH7.5The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.
CVE-2020-35129CRITICAL9Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, cou...
CVE-2020-35128CRITICAL9Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, ...
CVE-2020-23342HIGH8.8A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
CVE-2020-23522MEDIUM6.8Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
CVE-2020-20950MEDIUM5.9Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 201...
CVE-2020-28478HIGH7.5This affects the package gsap before 3.6.0.
CVE-2020-28477HIGH7.5This affects all versions of package immer.
CVE-2020-28472CRITICAL9.8This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an at...
CVE-2020-29450MEDIUM6.5Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's avai...
CVE-2020-36193HIGH7.5Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of sym...
CVE-2020-36192MEDIUM5.3An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the S...
CVE-2020-7343MEDIUM5.5Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee p...
CVE-2020-28476Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-23336. Reason: This candidate is a reservation d...
CVE-2020-28473MEDIUM6.8The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cl...
CVE-2020-29446MEDIUM5.3Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Ob...
CVE-2020-15864MEDIUM6.1An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a UR...
CVE-2020-25533HIGH7An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged ac...
CVE-2020-24641HIGH7.5In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated end...
CVE-2020-24640CRITICAL9.8There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a contai...
CVE-2020-24639CRITICAL9.8There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containe...
CVE-2020-24638HIGH7.2Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. Thes...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now