2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8117 | MEDIUM | 4.3 | 0.7% | Feb 4, 2020 | Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non... |
| CVE-2020-8115 | MEDIUM | 6.1 | 7.1% | Feb 4, 2020 | A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver ... |
| CVE-2020-3939 | MEDIUM | 6.1 | 0.7% | Feb 4, 2020 | SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Cross-Site Scripting(XSS), personal informa... |
| CVE-2020-5236 | MEDIUM | 6.5 | 2.6% | Feb 4, 2020 | Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a head... |
| CVE-2020-8549 | MEDIUM | 6.1 | 1.9% | Feb 3, 2020 | Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious ... |
| CVE-2020-8548 | MEDIUM | 6.1 | 1.4% | Feb 3, 2020 | massCode 1.0.0-alpha.6 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegrati... |
| CVE-2020-5182 | MEDIUM | 6.5 | 1.0% | Feb 3, 2020 | The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link t... |
| CVE-2020-4224 | MEDIUM | 5.5 | 0.2% | Feb 3, 2020 | IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain direc... |
| CVE-2020-7993 | MEDIUM | 4.3 | 0.7% | Feb 3, 2020 | Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a mo... |
| CVE-2020-8514 | MEDIUM | 6.1 | 0.8% | Feb 2, 2020 | An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript i... |
| CVE-2020-8516 | MEDIUM | 5.3 | 2.6% | Feb 2, 2020 | The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before att... |
| CVE-2020-8512 | MEDIUM | 6.1 | 14.8% | Feb 1, 2020 | In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter. |
| CVE-2020-8505 | MEDIUM | 6.5 | 1.1% | Jan 31, 2020 | School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user. |
| CVE-2020-8504 | MEDIUM | 6.5 | 1.1% | Jan 31, 2020 | School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrati... |
| CVE-2020-8503 | MEDIUM | 6.5 | 0.7% | Jan 31, 2020 | Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object ... |
| CVE-2020-5234 | MEDIUM | 6.5 | 1.6% | Jan 31, 2020 | MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS a... |
| CVE-2020-8422 | MEDIUM | 4.3 | 1.2% | Jan 31, 2020 | An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 1... |
| CVE-2020-7955 | MEDIUM | 5.3 | 1.4% | Jan 31, 2020 | HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resu... |
| CVE-2020-5526 | MEDIUM | 5.9 | 0.5% | Jan 31, 2020 | The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from server... |
| CVE-2020-8498 | MEDIUM | 5.4 | 1.2% | Jan 30, 2020 | XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gist... |
| CVE-2020-8496 | MEDIUM | 4.8 | 0.5% | Jan 30, 2020 | In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability b... |
| CVE-2020-8493 | MEDIUM | 4.8 | 1.5% | Jan 30, 2020 | A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via... |
| CVE-2020-5231 | MEDIUM | 6.5 | 0.6% | Jan 30, 2020 | In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new user... |
| CVE-2020-8095 | MEDIUM | 5.5 | 0.5% | Jan 30, 2020 | A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an at... |
| CVE-2020-8492 | MEDIUM | 6.5 | 6.6% | Jan 30, 2020 | Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTT... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now