2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4757MEDIUM6.4IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerab...
CVE-2020-4555MEDIUM5.4IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenti...
CVE-2020-27254HIGH7.5Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products a...
CVE-2020-26422MEDIUM5.3Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted c...
CVE-2020-26275MEDIUM6.1The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications ...
CVE-2020-25860MEDIUM6.6The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerab...
CVE-2020-14225MEDIUM6.5HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote una...
CVE-2020-35497MEDIUM6.5A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal informat...
CVE-2020-26263HIGH7.5tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before ve...
CVE-2020-17526HIGH7.7Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a maliciou...
CVE-2020-3999MEDIUM6.5VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware ...
CVE-2020-27846CRITICAL9.8A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authenticatio...
CVE-2020-35276CRITICAL9.8EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQ...
CVE-2020-35275MEDIUM5.4Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to an...
CVE-2020-35274MEDIUM4.8DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attac...
CVE-2020-35273HIGH8EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to ...
CVE-2020-26049MEDIUM6.1Nifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution.
CVE-2020-35590CRITICAL9.8LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per I...
CVE-2020-35589MEDIUM5.4The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-logi...
CVE-2020-29447MEDIUM4.3Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of ...
CVE-2020-35579HIGH7.5tindy2013 subconverter 0.6.4 has a /sub?target=%TARGET%&url=%URL%&config=%CONFIG% API endpoint that accepts an arbitrary...
CVE-2020-35573HIGH7.5srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timesta...
CVE-2020-7203CRITICAL9.8A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability ...
CVE-2020-7201HIGH8.8A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G...
CVE-2020-7200CRITICAL9.8A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerabili...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now