2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5233 | MEDIUM | 6.1 | 1.1% | Jan 30, 2020 | OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an atta... |
| CVE-2020-8092 | MEDIUM | 5.5 | 0.3% | Jan 30, 2020 | A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to ob... |
| CVE-2020-7913 | MEDIUM | 6.1 | 1.1% | Jan 30, 2020 | JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description. |
| CVE-2020-7912 | MEDIUM | 5.3 | 1.5% | Jan 30, 2020 | In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. |
| CVE-2020-7911 | MEDIUM | 6.1 | 0.6% | Jan 30, 2020 | In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS. |
| CVE-2020-7910 | MEDIUM | 5.4 | 0.5% | Jan 30, 2020 | JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role. |
| CVE-2020-7908 | MEDIUM | 4.3 | 0.8% | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages. |
| CVE-2020-8448 | MEDIUM | 5.5 | 0.5% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a ... |
| CVE-2020-8446 | MEDIUM | 5.5 | 0.5% | Jan 30, 2020 | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to pa... |
| CVE-2020-3758 | MEDIUM | 6.1 | 1.8% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cros... |
| CVE-2020-3717 | MEDIUM | 5.3 | 3.2% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traver... |
| CVE-2020-3715 | MEDIUM | 6.1 | 1.8% | Jan 29, 2020 | Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cros... |
| CVE-2020-2107 | MEDIUM | 4.3 | 0.6% | Jan 29, 2020 | Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenk... |
| CVE-2020-2106 | MEDIUM | 5.4 | 0.7% | Jan 29, 2020 | Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view,... |
| CVE-2020-2105 | MEDIUM | 5.4 | 1.8% | Jan 29, 2020 | REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks. |
| CVE-2020-2104 | MEDIUM | 4.3 | 1.1% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage cha... |
| CVE-2020-2103 | MEDIUM | 5.4 | 7.0% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI d... |
| CVE-2020-2102 | MEDIUM | 5.3 | 1.4% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC. |
| CVE-2020-2101 | MEDIUM | 5.3 | 1.4% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connec... |
| CVE-2020-2100 | MEDIUM | 5.8 | 3.4% | Jan 29, 2020 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service at... |
| CVE-2020-8426 | MEDIUM | 5.4 | 1.3% | Jan 28, 2020 | The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info ... |
| CVE-2020-8425 | MEDIUM | 6.5 | 1.2% | Jan 28, 2020 | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php. |
| CVE-2020-8421 | MEDIUM | 6.1 | 1.0% | Jan 28, 2020 | An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs. |
| CVE-2020-8315 | MEDIUM | 5.5 | 1.3% | Jan 28, 2020 | In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launc... |
| CVE-2020-7934 | MEDIUM | 5.4 | 4.5% | Jan 28, 2020 | In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now