2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-1958MEDIUM6.5When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials c...
CVE-2020-8966MEDIUM6.1There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages ...
CVE-2020-1954MEDIUM5.3Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If...
CVE-2020-11466MEDIUM4.3An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privi...
CVE-2020-11464MEDIUM4.3An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privil...
CVE-2020-10598MEDIUM6.1In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment es...
CVE-2020-5290MEDIUM6.5In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` has...
CVE-2020-1934MEDIUM5.3In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP serve...
CVE-2020-1949MEDIUM6.1Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elem...
CVE-2020-1943MEDIUM6.1Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
CVE-2020-10203MEDIUM4.8Sonatype Nexus Repository before 3.21.2 allows XSS.
CVE-2020-9784MEDIUM4.3A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use a...
CVE-2020-9781MEDIUM5.3The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPa...
CVE-2020-9777MEDIUM5.3An issue existed in the selection of video file by Mail. The issue was fixed by selecting the latest version of a video....
CVE-2020-9775MEDIUM5.3An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved stat...
CVE-2020-9770MEDIUM6.5A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker...
CVE-2020-3917MEDIUM5.5This issue was addressed with a new entitlement. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2...
CVE-2020-3916MEDIUM5.3An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, wat...
CVE-2020-3914MEDIUM5.5A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13...
CVE-2020-3902MEDIUM6.1An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.4 and iPadOS 13.4,...
CVE-2020-3890MEDIUM5.3The issue was addressed with improved deletion. This issue is fixed in iOS 13.4 and iPadOS 13.4. Deleted messages groups...
CVE-2020-3889MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user ...
CVE-2020-3888MEDIUM4.3A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4. A maliciously c...
CVE-2020-3887MEDIUM4.3A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safa...
CVE-2020-3885MEDIUM4.3A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safa...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now