2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-26288MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm pac...
CVE-2020-35849HIGH7.5An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unp...
CVE-2020-29231MEDIUM5.4EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the A...
CVE-2020-29230MEDIUM6.1EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the A...
CVE-2020-29228HIGH7.5EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Pag...
CVE-2020-28925MEDIUM5.3Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with ...
CVE-2020-28736HIGH8.8Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.M...
CVE-2020-28735HIGH8.8Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
CVE-2020-28734HIGH8.8Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
CVE-2020-28365MEDIUM6.1Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For ...
CVE-2020-27848HIGH8.8dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOr...
CVE-2020-26247MEDIUM4.3Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri befo...
CVE-2020-5811MEDIUM6.5An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, whi...
CVE-2020-5810MEDIUM5.4A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media c...
CVE-2020-5809MEDIUM5.4A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScr...
CVE-2020-35241MEDIUM4.8FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an...
CVE-2020-35240MEDIUM4.8FluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an at...
CVE-2020-29477MEDIUM4.8Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow...
CVE-2020-29469MEDIUM5.4WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacke...
CVE-2020-29233MEDIUM5.4WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allo...
CVE-2020-29594CRITICAL9.8Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3...
CVE-2020-35850MEDIUM6.5An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product...
CVE-2020-35848CRITICAL9.8Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
CVE-2020-35847CRITICAL9.8Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
CVE-2020-35846CRITICAL9.8Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now