2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-11652MEDIUM6.5An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla...
CVE-2020-10691MEDIUM5.2An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy col...
CVE-2020-6579MEDIUM6.1Cross-site scripting (XSS) vulnerability in mailhive/cloudbeez/cloudloader.php and mailhive/cloudbeez/cloudloader_core.p...
CVE-2020-12101MEDIUM4.3The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's st...
CVE-2020-9387MEDIUM4.3In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for acc...
CVE-2020-12283MEDIUM6.1Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL...
CVE-2020-11022MEDIUM6.1In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one...
CVE-2020-12469MEDIUM6.5admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized ...
CVE-2020-12467MEDIUM6.5Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie.
CVE-2020-11023MEDIUM6.1In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untru...
CVE-2020-12472MEDIUM5.4MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
CVE-2020-12465MEDIUM6.7An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel be...
CVE-2020-12464MEDIUM6.7usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occ...
CVE-2020-12462MEDIUM6.1The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
CVE-2020-12277MEDIUM5.3GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activ...
CVE-2020-12276MEDIUM4.8GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.
CVE-2020-12275MEDIUM5.3GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snipp...
CVE-2020-11009MEDIUM6.5In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job de...
CVE-2020-12459MEDIUM5.5In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/gra...
CVE-2020-12458MEDIUM5.5An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database ...
CVE-2020-12252MEDIUM6.2An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an au...
CVE-2020-10797MEDIUM6.1An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After pass...
CVE-2020-7453MEDIUM6In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE...
CVE-2020-12261MEDIUM5.4Open-AudIT 3.3.0 allows an XSS attack after login.
CVE-2020-12438MEDIUM5.4An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only securi...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now