2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29006CRITICAL9.8MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyEleme...
CVE-2020-25475CRITICAL9.8SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
CVE-2020-25474MEDIUM6.1SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name p...
CVE-2020-25473MEDIUM6.5SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies.
CVE-2020-25472MEDIUM6.5SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows ...
CVE-2020-5674HIGH7.8Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privil...
CVE-2020-5641MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers...
CVE-2020-29003MEDIUM5.4The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Spec...
CVE-2020-29002MEDIUM4.8includes/CologneBlueTemplate.php in the CologneBlue skin for MediaWiki through 1.35 allows XSS via a qbfind message supp...
CVE-2020-28348MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not exp...
CVE-2020-26890HIGH7.5Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.ro...
CVE-2020-15929CRITICAL9.8In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow ...
CVE-2020-15928MEDIUM5.3In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory trav...
CVE-2020-28991CRITICAL9.8Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also...
CVE-2020-4006CRITICAL9.1VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command i...
CVE-2020-28984CRITICAL9.8prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, displ...
CVE-2020-26229LOW3.7TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.1...
CVE-2020-25696HIGH7.5A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, befo...
CVE-2020-25688LOW3.5A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned...
CVE-2020-25660HIGH8.8A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not ve...
CVE-2020-28360CRITICAL9.8Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in ind...
CVE-2020-26231MEDIUM6.7October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 ...
CVE-2020-26228HIGH7.5TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user sessio...
CVE-2020-26227MEDIUM6.1TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system ...
CVE-2020-24227HIGH7.5Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with a...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now