2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11652 | MEDIUM | 6.5 | 86.1% | Apr 30, 2020 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla... |
| CVE-2020-10691 | MEDIUM | 5.2 | 0.4% | Apr 30, 2020 | An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy col... |
| CVE-2020-6579 | MEDIUM | 6.1 | 0.8% | Apr 30, 2020 | Cross-site scripting (XSS) vulnerability in mailhive/cloudbeez/cloudloader.php and mailhive/cloudbeez/cloudloader_core.p... |
| CVE-2020-12101 | MEDIUM | 4.3 | 2.0% | Apr 30, 2020 | The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's st... |
| CVE-2020-9387 | MEDIUM | 4.3 | 0.7% | Apr 30, 2020 | In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for acc... |
| CVE-2020-12283 | MEDIUM | 6.1 | 1.3% | Apr 30, 2020 | Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL... |
| CVE-2020-11022 | MEDIUM | 6.1 | 99.0% | Apr 29, 2020 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one... |
| CVE-2020-12469 | MEDIUM | 6.5 | 0.9% | Apr 29, 2020 | admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized ... |
| CVE-2020-12467 | MEDIUM | 6.5 | 0.9% | Apr 29, 2020 | Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie. |
| CVE-2020-11023 | MEDIUM | 6.1 | 83.8% | Apr 29, 2020 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untru... |
| CVE-2020-12472 | MEDIUM | 5.4 | 0.5% | Apr 29, 2020 | MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description. |
| CVE-2020-12465 | MEDIUM | 6.7 | 0.4% | Apr 29, 2020 | An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel be... |
| CVE-2020-12464 | MEDIUM | 6.7 | 0.8% | Apr 29, 2020 | usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occ... |
| CVE-2020-12462 | MEDIUM | 6.1 | 0.5% | Apr 29, 2020 | The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. |
| CVE-2020-12277 | MEDIUM | 5.3 | 0.8% | Apr 29, 2020 | GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activ... |
| CVE-2020-12276 | MEDIUM | 4.8 | 0.6% | Apr 29, 2020 | GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature. |
| CVE-2020-12275 | MEDIUM | 5.3 | 1.0% | Apr 29, 2020 | GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snipp... |
| CVE-2020-11009 | MEDIUM | 6.5 | 1.4% | Apr 29, 2020 | In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job de... |
| CVE-2020-12459 | MEDIUM | 5.5 | 0.3% | Apr 29, 2020 | In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/gra... |
| CVE-2020-12458 | MEDIUM | 5.5 | 0.5% | Apr 29, 2020 | An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database ... |
| CVE-2020-12252 | MEDIUM | 6.2 | 2.0% | Apr 29, 2020 | An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an au... |
| CVE-2020-10797 | MEDIUM | 6.1 | 2.3% | Apr 29, 2020 | An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After pass... |
| CVE-2020-7453 | MEDIUM | 6 | 0.3% | Apr 29, 2020 | In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE... |
| CVE-2020-12261 | MEDIUM | 5.4 | 2.6% | Apr 28, 2020 | Open-AudIT 3.3.0 allows an XSS attack after login. |
| CVE-2020-12438 | MEDIUM | 5.4 | 0.6% | Apr 28, 2020 | An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only securi... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now