2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-10116MEDIUM5.3cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI ca...
CVE-2020-10114MEDIUM6.1cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).
CVE-2020-10113MEDIUM6.1cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).
CVE-2020-6646MEDIUM5.4An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored...
CVE-2020-6175MEDIUM5.9Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.
CVE-2020-9472MEDIUM6.5Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package f...
CVE-2020-7608MEDIUM5.3yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
CVE-2020-7916MEDIUM6.5be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered u...
CVE-2020-6586MEDIUM5.4Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /adm...
CVE-2020-6584MEDIUM6.5Nagios Log Server 2.1.3 has Incorrect Access Control.
CVE-2020-1740MEDIUM4.7A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-v...
CVE-2020-1735MEDIUM4.6A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a n...
CVE-2020-10242MEDIUM6.1An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaSc...
CVE-2020-10240MEDIUM5.3An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of us...
CVE-2020-1753MEDIUM5.5A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prio...
CVE-2020-9518MEDIUM5.3Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions ...
CVE-2020-9519MEDIUM5.3HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.4...
CVE-2020-0088MEDIUM6.5In parseTrackFragmentRun of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. ...
CVE-2020-10577MEDIUM4.8An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property ...
CVE-2020-10576MEDIUM5.9An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition t...
CVE-2020-10575MEDIUM4.2An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session man...
CVE-2020-10076MEDIUM6.1GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge ...
CVE-2020-10075MEDIUM6.1GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or ...
CVE-2020-10218MEDIUM6.5A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter b...
CVE-2020-10092MEDIUM6.1GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now