2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-1958 | MEDIUM | 6.5 | 4.6% | Apr 1, 2020 | When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials c... |
| CVE-2020-8966 | MEDIUM | 6.1 | 0.8% | Apr 1, 2020 | There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages ... |
| CVE-2020-1954 | MEDIUM | 5.3 | 6.1% | Apr 1, 2020 | Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If... |
| CVE-2020-11466 | MEDIUM | 4.3 | 1.2% | Apr 1, 2020 | An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privi... |
| CVE-2020-11464 | MEDIUM | 4.3 | 1.2% | Apr 1, 2020 | An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privil... |
| CVE-2020-10598 | MEDIUM | 6.1 | 0.3% | Apr 1, 2020 | In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment es... |
| CVE-2020-5290 | MEDIUM | 6.5 | 0.8% | Apr 1, 2020 | In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` has... |
| CVE-2020-1934 | MEDIUM | 5.3 | 52.0% | Apr 1, 2020 | In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP serve... |
| CVE-2020-1949 | MEDIUM | 6.1 | 2.0% | Apr 1, 2020 | Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elem... |
| CVE-2020-1943 | MEDIUM | 6.1 | 97.3% | Apr 1, 2020 | Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07. |
| CVE-2020-10203 | MEDIUM | 4.8 | 0.9% | Apr 1, 2020 | Sonatype Nexus Repository before 3.21.2 allows XSS. |
| CVE-2020-9784 | MEDIUM | 4.3 | 0.8% | Apr 1, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use a... |
| CVE-2020-9781 | MEDIUM | 5.3 | 0.8% | Apr 1, 2020 | The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPa... |
| CVE-2020-9777 | MEDIUM | 5.3 | 0.8% | Apr 1, 2020 | An issue existed in the selection of video file by Mail. The issue was fixed by selecting the latest version of a video.... |
| CVE-2020-9775 | MEDIUM | 5.3 | 0.9% | Apr 1, 2020 | An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved stat... |
| CVE-2020-9770 | MEDIUM | 6.5 | 1.2% | Apr 1, 2020 | A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker... |
| CVE-2020-3917 | MEDIUM | 5.5 | 0.3% | Apr 1, 2020 | This issue was addressed with a new entitlement. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2... |
| CVE-2020-3916 | MEDIUM | 5.3 | 0.8% | Apr 1, 2020 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, wat... |
| CVE-2020-3914 | MEDIUM | 5.5 | 0.8% | Apr 1, 2020 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13... |
| CVE-2020-3902 | MEDIUM | 6.1 | 1.1% | Apr 1, 2020 | An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.4 and iPadOS 13.4,... |
| CVE-2020-3890 | MEDIUM | 5.3 | 0.8% | Apr 1, 2020 | The issue was addressed with improved deletion. This issue is fixed in iOS 13.4 and iPadOS 13.4. Deleted messages groups... |
| CVE-2020-3889 | MEDIUM | 5.5 | 0.3% | Apr 1, 2020 | A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user ... |
| CVE-2020-3888 | MEDIUM | 4.3 | 0.7% | Apr 1, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4. A maliciously c... |
| CVE-2020-3887 | MEDIUM | 4.3 | 1.2% | Apr 1, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safa... |
| CVE-2020-3885 | MEDIUM | 4.3 | 1.7% | Apr 1, 2020 | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safa... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now