2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-26288 | MEDIUM | 6.5 | 0.8% | Dec 30, 2020 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm pac... |
| CVE-2020-35849 | HIGH | 7.5 | 1.6% | Dec 30, 2020 | An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unp... |
| CVE-2020-29231 | MEDIUM | 5.4 | 0.6% | Dec 30, 2020 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the A... |
| CVE-2020-29230 | MEDIUM | 6.1 | 0.8% | Dec 30, 2020 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the A... |
| CVE-2020-29228 | HIGH | 7.5 | 1.2% | Dec 30, 2020 | EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Pag... |
| CVE-2020-28925 | MEDIUM | 5.3 | 1.1% | Dec 30, 2020 | Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with ... |
| CVE-2020-28736 | HIGH | 8.8 | 1.1% | Dec 30, 2020 | Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.M... |
| CVE-2020-28735 | HIGH | 8.8 | 1.1% | Dec 30, 2020 | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). |
| CVE-2020-28734 | HIGH | 8.8 | 1.1% | Dec 30, 2020 | Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. |
| CVE-2020-28365 | MEDIUM | 6.1 | 0.7% | Dec 30, 2020 | Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For ... |
| CVE-2020-27848 | HIGH | 8.8 | 1.2% | Dec 30, 2020 | dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOr... |
| CVE-2020-26247 | MEDIUM | 4.3 | 1.3% | Dec 30, 2020 | Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri befo... |
| CVE-2020-5811 | MEDIUM | 6.5 | 9.4% | Dec 30, 2020 | An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, whi... |
| CVE-2020-5810 | MEDIUM | 5.4 | 66.2% | Dec 30, 2020 | A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media c... |
| CVE-2020-5809 | MEDIUM | 5.4 | 0.7% | Dec 30, 2020 | A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScr... |
| CVE-2020-35241 | MEDIUM | 4.8 | 2.1% | Dec 30, 2020 | FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an... |
| CVE-2020-35240 | MEDIUM | 4.8 | 1.0% | Dec 30, 2020 | FluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an at... |
| CVE-2020-29477 | MEDIUM | 4.8 | 1.1% | Dec 30, 2020 | Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow... |
| CVE-2020-29469 | MEDIUM | 5.4 | 1.4% | Dec 30, 2020 | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacke... |
| CVE-2020-29233 | MEDIUM | 5.4 | 1.3% | Dec 30, 2020 | WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allo... |
| CVE-2020-29594 | CRITICAL | 9.8 | 1.6% | Dec 30, 2020 | Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3... |
| CVE-2020-35850 | MEDIUM | 6.5 | 1.6% | Dec 30, 2020 | An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product... |
| CVE-2020-35848 | CRITICAL | 9.8 | 75.0% | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. |
| CVE-2020-35847 | CRITICAL | 9.8 | 98.3% | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. |
| CVE-2020-35846 | CRITICAL | 9.8 | 93.2% | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now