2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-3791MEDIUM4.3Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds ...
CVE-2020-3782MEDIUM4.3Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds ...
CVE-2020-3781MEDIUM4.3Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds ...
CVE-2020-3778MEDIUM4.3Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful expl...
CVE-2020-3771MEDIUM4.3Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds ...
CVE-2020-3808MEDIUM5.9Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition ...
CVE-2020-5277MEDIUM5.4PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is f...
CVE-2020-2170MEDIUM5.4Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote...
CVE-2020-2169MEDIUM6.1A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter di...
CVE-2020-2164MEDIUM6.5Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configurat...
CVE-2020-2163MEDIUM5.4Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, result...
CVE-2020-2162MEDIUM5.4Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as fi...
CVE-2020-2161MEDIUM5.4Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form valid...
CVE-2020-10791MEDIUM6.5app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authe...
CVE-2020-10790MEDIUM5.4openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
CVE-2020-5559MEDIUM6.1Cross-site scripting vulnerability in WL-Enq 1.11 and 1.12 allows remote attackers to inject arbitrary web script or HTM...
CVE-2020-5557MEDIUM6.1Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via ...
CVE-2020-5552MEDIUM6.1Cross-site scripting vulnerability in mailform version 1.04 allows remote attackers to inject arbitrary web script or HT...
CVE-2020-5261MEDIUM6.8Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5...
CVE-2020-6816MEDIUM6.1In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted an...
CVE-2020-6802MEDIUM6.1In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allo...
CVE-2020-10942MEDIUM5.3In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which mi...
CVE-2020-10941MEDIUM5.9Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usag...
CVE-2020-10855MEDIUM4.6An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (F...
CVE-2020-10853MEDIUM5.3An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. The Samsung IDs are S...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now