2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12105 | MEDIUM | 5.9 | 1.7% | Apr 23, 2020 | OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers... |
| CVE-2020-7643 | MEDIUM | 5.3 | 1.0% | Apr 23, 2020 | paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function c... |
| CVE-2020-4353 | MEDIUM | 4.6 | 0.3% | Apr 23, 2020 | IBM MaaS360 6.82 could allow a user with pysical access to the device to crash the application which may enable the user... |
| CVE-2020-1760 | MEDIUM | 6.1 | 1.5% | Apr 23, 2020 | A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw... |
| CVE-2020-12054 | MEDIUM | 6.1 | 3.6% | Apr 23, 2020 | The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also a... |
| CVE-2020-11806 | MEDIUM | 5.9 | 0.5% | Apr 23, 2020 | In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the v... |
| CVE-2020-12071 | MEDIUM | 4.8 | 0.6% | Apr 23, 2020 | Anchor 0.12.7 allows admins to cause XSS via crafted post content. |
| CVE-2020-8833 | MEDIUM | 4.7 | 0.3% | Apr 22, 2020 | Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible ... |
| CVE-2020-8831 | MEDIUM | 5.5 | 0.7% | Apr 22, 2020 | Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the a... |
| CVE-2020-1983 | MEDIUM | 6.5 | 2.3% | Apr 22, 2020 | A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets t... |
| CVE-2020-11649 | MEDIUM | 6.5 | 0.8% | Apr 22, 2020 | An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the gr... |
| CVE-2020-7642 | MEDIUM | 5.4 | 0.9% | Apr 22, 2020 | lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the vide... |
| CVE-2020-4085 | MEDIUM | 6.5 | 0.8% | Apr 22, 2020 | "HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace ... |
| CVE-2020-11938 | MEDIUM | 4.9 | 0.9% | Apr 22, 2020 | In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters use... |
| CVE-2020-11689 | MEDIUM | 6.5 | 0.6% | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the setti... |
| CVE-2020-11416 | MEDIUM | 5.4 | 0.5% | Apr 22, 2020 | JetBrains Space through 2020-04-22 allows stored XSS in Chats. |
| CVE-2020-11891 | MEDIUM | 5.3 | 0.8% | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow th... |
| CVE-2020-11890 | MEDIUM | 5.3 | 2.8% | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to ... |
| CVE-2020-11889 | MEDIUM | 5.3 | 0.8% | Apr 21, 2020 | An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow th... |
| CVE-2020-8099 | MEDIUM | 6.2 | 0.4% | Apr 21, 2020 | A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to su... |
| CVE-2020-11944 | MEDIUM | 6.1 | 1.2% | Apr 20, 2020 | Abe (aka bitcoin-abe) through 0.7.2, and 0.8pre, allows XSS in __call__ in abe.py because the PATH_INFO environment vari... |
| CVE-2020-9445 | MEDIUM | 6.1 | 0.7% | Apr 20, 2020 | Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality. |
| CVE-2020-9444 | MEDIUM | 6.1 | 0.7% | Apr 20, 2020 | Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality. |
| CVE-2020-9070 | MEDIUM | 5.5 | 0.6% | Apr 20, 2020 | Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulne... |
| CVE-2020-1803 | MEDIUM | 5.3 | 0.3% | Apr 20, 2020 | Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now