2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28482 | HIGH | 8.8 | 1.0% | Jan 19, 2021 | This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the... |
| CVE-2020-28481 | MEDIUM | 4.3 | 0.7% | Jan 19, 2021 | The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whi... |
| CVE-2020-28480 | CRITICAL | 9.8 | 1.4% | Jan 19, 2021 | The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com... |
| CVE-2020-28479 | HIGH | 7.5 | 2.0% | Jan 19, 2021 | The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function. |
| CVE-2020-35129 | CRITICAL | 9 | 1.0% | Jan 19, 2021 | Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, cou... |
| CVE-2020-35128 | CRITICAL | 9 | 1.7% | Jan 19, 2021 | Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, ... |
| CVE-2020-23342 | HIGH | 8.8 | 12.4% | Jan 19, 2021 | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. |
| CVE-2020-23522 | MEDIUM | 6.8 | 2.0% | Jan 19, 2021 | Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter. |
| CVE-2020-20950 | MEDIUM | 5.9 | 0.9% | Jan 19, 2021 | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 201... |
| CVE-2020-28478 | HIGH | 7.5 | 1.6% | Jan 19, 2021 | This affects the package gsap before 3.6.0. |
| CVE-2020-28477 | HIGH | 7.5 | 2.3% | Jan 19, 2021 | This affects all versions of package immer. |
| CVE-2020-28472 | CRITICAL | 9.8 | 2.1% | Jan 19, 2021 | This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an at... |
| CVE-2020-29450 | MEDIUM | 6.5 | 2.2% | Jan 19, 2021 | Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's avai... |
| CVE-2020-36193 | HIGH | 7.5 | 70.6% | Jan 18, 2021 | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of sym... |
| CVE-2020-36192 | MEDIUM | 5.3 | 1.0% | Jan 18, 2021 | An issue was discovered in the Source Integration plugin before 2.4.1 for MantisBT. An attacker can gain access to the S... |
| CVE-2020-7343 | MEDIUM | 5.5 | 0.4% | Jan 18, 2021 | Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee p... |
| CVE-2020-28476 | — | — | — | Jan 18, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-23336. Reason: This candidate is a reservation d... |
| CVE-2020-28473 | MEDIUM | 6.8 | 1.8% | Jan 18, 2021 | The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cl... |
| CVE-2020-29446 | MEDIUM | 5.3 | 1.1% | Jan 18, 2021 | Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Ob... |
| CVE-2020-15864 | MEDIUM | 6.1 | 0.7% | Jan 17, 2021 | An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a UR... |
| CVE-2020-25533 | HIGH | 7 | 0.3% | Jan 15, 2021 | An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged ac... |
| CVE-2020-24641 | HIGH | 7.5 | 1.5% | Jan 15, 2021 | In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated end... |
| CVE-2020-24640 | CRITICAL | 9.8 | 2.9% | Jan 15, 2021 | There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a contai... |
| CVE-2020-24639 | CRITICAL | 9.8 | 7.2% | Jan 15, 2021 | There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containe... |
| CVE-2020-24638 | HIGH | 7.2 | 3.2% | Jan 15, 2021 | Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. Thes... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now