2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-1728MEDIUM5.4A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are ...
CVE-2020-7639MEDIUM5.3eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or ...
CVE-2020-7638MEDIUM5.3confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding ...
CVE-2020-7637MEDIUM5.3class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could ...
CVE-2020-11565MEDIUM6An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bou...
CVE-2020-11547MEDIUM5.3PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes runn...
CVE-2020-11533MEDIUM5.5Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive info...
CVE-2020-11529MEDIUM6.1Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
CVE-2020-8143MEDIUM6.1An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn14...
CVE-2020-8142MEDIUM6.8A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoa...
CVE-2020-10960MEDIUM5.3In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is...
CVE-2020-10689MEDIUM6.8A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An...
CVE-2020-11499MEDIUM6.1Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request...
CVE-2020-11494MEDIUM4.4An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attacke...
CVE-2020-11453MEDIUM5.3Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed throug...
CVE-2020-11452MEDIUM4.3Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URL...
CVE-2020-4325MEDIUM6.5The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not pr...
CVE-2020-4304MEDIUM6.1IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnera...
CVE-2020-4303MEDIUM6.1IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnera...
CVE-2020-11454MEDIUM5.4Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowin...
CVE-2020-8017MEDIUM6.3A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Ent...
CVE-2020-11491MEDIUM4.9Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attac...
CVE-2020-11458MEDIUM4.9app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MIS...
CVE-2020-1927MEDIUM6.1In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential m...
CVE-2020-8145MEDIUM6.5The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoint...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now