2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3791 | MEDIUM | 4.3 | 2.2% | Mar 25, 2020 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds ... |
| CVE-2020-3782 | MEDIUM | 4.3 | 2.2% | Mar 25, 2020 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds ... |
| CVE-2020-3781 | MEDIUM | 4.3 | 2.2% | Mar 25, 2020 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds ... |
| CVE-2020-3778 | MEDIUM | 4.3 | 2.2% | Mar 25, 2020 | Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful expl... |
| CVE-2020-3771 | MEDIUM | 4.3 | 2.2% | Mar 25, 2020 | Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds ... |
| CVE-2020-3808 | MEDIUM | 5.9 | 1.4% | Mar 25, 2020 | Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition ... |
| CVE-2020-5277 | MEDIUM | 5.4 | 0.7% | Mar 25, 2020 | PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is f... |
| CVE-2020-2170 | MEDIUM | 5.4 | 0.7% | Mar 25, 2020 | Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote... |
| CVE-2020-2169 | MEDIUM | 6.1 | 1.0% | Mar 25, 2020 | A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter di... |
| CVE-2020-2164 | MEDIUM | 6.5 | 0.8% | Mar 25, 2020 | Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configurat... |
| CVE-2020-2163 | MEDIUM | 5.4 | 1.2% | Mar 25, 2020 | Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, result... |
| CVE-2020-2162 | MEDIUM | 5.4 | 1.2% | Mar 25, 2020 | Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as fi... |
| CVE-2020-2161 | MEDIUM | 5.4 | 1.2% | Mar 25, 2020 | Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form valid... |
| CVE-2020-10791 | MEDIUM | 6.5 | 1.2% | Mar 25, 2020 | app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authe... |
| CVE-2020-10790 | MEDIUM | 5.4 | 0.9% | Mar 25, 2020 | openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. |
| CVE-2020-5559 | MEDIUM | 6.1 | 0.8% | Mar 25, 2020 | Cross-site scripting vulnerability in WL-Enq 1.11 and 1.12 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2020-5557 | MEDIUM | 6.1 | 0.8% | Mar 25, 2020 | Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via ... |
| CVE-2020-5552 | MEDIUM | 6.1 | 0.8% | Mar 25, 2020 | Cross-site scripting vulnerability in mailform version 1.04 allows remote attackers to inject arbitrary web script or HT... |
| CVE-2020-5261 | MEDIUM | 6.8 | 1.2% | Mar 25, 2020 | Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5... |
| CVE-2020-6816 | MEDIUM | 6.1 | 1.3% | Mar 24, 2020 | In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted an... |
| CVE-2020-6802 | MEDIUM | 6.1 | 1.7% | Mar 24, 2020 | In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allo... |
| CVE-2020-10942 | MEDIUM | 5.3 | 1.0% | Mar 24, 2020 | In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which mi... |
| CVE-2020-10941 | MEDIUM | 5.9 | 1.5% | Mar 24, 2020 | Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usag... |
| CVE-2020-10855 | MEDIUM | 4.6 | 0.1% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (F... |
| CVE-2020-10853 | MEDIUM | 5.3 | 0.3% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. The Samsung IDs are S... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now