2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10116 | MEDIUM | 5.3 | 0.8% | Mar 17, 2020 | cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI ca... |
| CVE-2020-10114 | MEDIUM | 6.1 | 0.6% | Mar 17, 2020 | cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). |
| CVE-2020-10113 | MEDIUM | 6.1 | 0.6% | Mar 17, 2020 | cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515). |
| CVE-2020-6646 | MEDIUM | 5.4 | 0.8% | Mar 17, 2020 | An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored... |
| CVE-2020-6175 | MEDIUM | 5.9 | 0.6% | Mar 16, 2020 | Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. |
| CVE-2020-9472 | MEDIUM | 6.5 | 2.1% | Mar 16, 2020 | Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package f... |
| CVE-2020-7608 | MEDIUM | 5.3 | 0.5% | Mar 16, 2020 | yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload. |
| CVE-2020-7916 | MEDIUM | 6.5 | 1.1% | Mar 16, 2020 | be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered u... |
| CVE-2020-6586 | MEDIUM | 5.4 | 27.3% | Mar 16, 2020 | Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /adm... |
| CVE-2020-6584 | MEDIUM | 6.5 | 3.9% | Mar 16, 2020 | Nagios Log Server 2.1.3 has Incorrect Access Control. |
| CVE-2020-1740 | MEDIUM | 4.7 | 0.4% | Mar 16, 2020 | A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-v... |
| CVE-2020-1735 | MEDIUM | 4.6 | 0.5% | Mar 16, 2020 | A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a n... |
| CVE-2020-10242 | MEDIUM | 6.1 | 1.0% | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaSc... |
| CVE-2020-10240 | MEDIUM | 5.3 | 1.2% | Mar 16, 2020 | An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of us... |
| CVE-2020-1753 | MEDIUM | 5.5 | 0.5% | Mar 16, 2020 | A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prio... |
| CVE-2020-9518 | MEDIUM | 5.3 | 0.9% | Mar 16, 2020 | Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions ... |
| CVE-2020-9519 | MEDIUM | 5.3 | 0.9% | Mar 16, 2020 | HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.4... |
| CVE-2020-0088 | MEDIUM | 6.5 | 0.7% | Mar 15, 2020 | In parseTrackFragmentRun of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. ... |
| CVE-2020-10577 | MEDIUM | 4.8 | 0.5% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property ... |
| CVE-2020-10576 | MEDIUM | 5.9 | 0.6% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition t... |
| CVE-2020-10575 | MEDIUM | 4.2 | 0.5% | Mar 14, 2020 | An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session man... |
| CVE-2020-10076 | MEDIUM | 6.1 | 0.7% | Mar 13, 2020 | GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge ... |
| CVE-2020-10075 | MEDIUM | 6.1 | 0.7% | Mar 13, 2020 | GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or ... |
| CVE-2020-10218 | MEDIUM | 6.5 | 1.2% | Mar 13, 2020 | A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter b... |
| CVE-2020-10092 | MEDIUM | 6.1 | 0.7% | Mar 13, 2020 | GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now