2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-12105MEDIUM5.9OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers...
CVE-2020-7643MEDIUM5.3paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function c...
CVE-2020-4353MEDIUM4.6IBM MaaS360 6.82 could allow a user with pysical access to the device to crash the application which may enable the user...
CVE-2020-1760MEDIUM6.1A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw...
CVE-2020-12054MEDIUM6.1The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also a...
CVE-2020-11806MEDIUM5.9In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the v...
CVE-2020-12071MEDIUM4.8Anchor 0.12.7 allows admins to cause XSS via crafted post content.
CVE-2020-8833MEDIUM4.7Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible ...
CVE-2020-8831MEDIUM5.5Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the a...
CVE-2020-1983MEDIUM6.5A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets t...
CVE-2020-11649MEDIUM6.5An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the gr...
CVE-2020-7642MEDIUM5.4lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the vide...
CVE-2020-4085MEDIUM6.5"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace ...
CVE-2020-11938MEDIUM4.9In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters use...
CVE-2020-11689MEDIUM6.5In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the setti...
CVE-2020-11416MEDIUM5.4JetBrains Space through 2020-04-22 allows stored XSS in Chats.
CVE-2020-11891MEDIUM5.3An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow th...
CVE-2020-11890MEDIUM5.3An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to ...
CVE-2020-11889MEDIUM5.3An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow th...
CVE-2020-8099MEDIUM6.2A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to su...
CVE-2020-11944MEDIUM6.1Abe (aka bitcoin-abe) through 0.7.2, and 0.8pre, allows XSS in __call__ in abe.py because the PATH_INFO environment vari...
CVE-2020-9445MEDIUM6.1Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
CVE-2020-9444MEDIUM6.1Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
CVE-2020-9070MEDIUM5.5Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulne...
CVE-2020-1803MEDIUM5.3Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now