2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-29006 | CRITICAL | 9.8 | 1.2% | Nov 24, 2020 | MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyEleme... |
| CVE-2020-25475 | CRITICAL | 9.8 | 1.1% | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action. |
| CVE-2020-25474 | MEDIUM | 6.1 | 0.9% | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name p... |
| CVE-2020-25473 | MEDIUM | 6.5 | 0.9% | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies. |
| CVE-2020-25472 | MEDIUM | 6.5 | 0.5% | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows ... |
| CVE-2020-5674 | HIGH | 7.8 | 0.3% | Nov 24, 2020 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privil... |
| CVE-2020-5641 | MEDIUM | 6.5 | 0.6% | Nov 24, 2020 | Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers... |
| CVE-2020-29003 | MEDIUM | 5.4 | 0.5% | Nov 24, 2020 | The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Spec... |
| CVE-2020-29002 | MEDIUM | 4.8 | 0.5% | Nov 24, 2020 | includes/CologneBlueTemplate.php in the CologneBlue skin for MediaWiki through 1.35 allows XSS via a qbfind message supp... |
| CVE-2020-28348 | MEDIUM | 6.5 | 1.6% | Nov 24, 2020 | HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not exp... |
| CVE-2020-26890 | HIGH | 7.5 | 3.0% | Nov 24, 2020 | Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.ro... |
| CVE-2020-15929 | CRITICAL | 9.8 | 4.5% | Nov 24, 2020 | In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow ... |
| CVE-2020-15928 | MEDIUM | 5.3 | 1.7% | Nov 24, 2020 | In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory trav... |
| CVE-2020-28991 | CRITICAL | 9.8 | 1.7% | Nov 24, 2020 | Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also... |
| CVE-2020-4006 | CRITICAL | 9.1 | 23.8% | Nov 23, 2020 | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command i... |
| CVE-2020-28984 | CRITICAL | 9.8 | 2.2% | Nov 23, 2020 | prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, displ... |
| CVE-2020-26229 | LOW | 3.7 | 0.6% | Nov 23, 2020 | TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.1... |
| CVE-2020-25696 | HIGH | 7.5 | 2.6% | Nov 23, 2020 | A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, befo... |
| CVE-2020-25688 | LOW | 3.5 | 0.2% | Nov 23, 2020 | A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned... |
| CVE-2020-25660 | HIGH | 8.8 | 1.0% | Nov 23, 2020 | A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not ve... |
| CVE-2020-28360 | CRITICAL | 9.8 | 2.9% | Nov 23, 2020 | Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in ind... |
| CVE-2020-26231 | MEDIUM | 6.7 | 0.3% | Nov 23, 2020 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 ... |
| CVE-2020-26228 | HIGH | 7.5 | 0.7% | Nov 23, 2020 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 user sessio... |
| CVE-2020-26227 | MEDIUM | 6.1 | 0.7% | Nov 23, 2020 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.23 and 10.4.10 the system ... |
| CVE-2020-24227 | HIGH | 7.5 | 1.4% | Nov 23, 2020 | Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with a... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now