2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4700HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenti...
CVE-2020-4692MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenti...
CVE-2020-4672MEDIUM5.4IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2020-4671MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sens...
CVE-2020-4665MEDIUM4.3IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on autho...
CVE-2020-4655HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL in...
CVE-2020-4647HIGH8.8IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote a...
CVE-2020-4566MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially high...
CVE-2020-4476HIGH7.5IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain se...
CVE-2020-4475MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote at...
CVE-2020-28723HIGH7.5Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.
CVE-2020-27991MEDIUM5.4Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
CVE-2020-27990MEDIUM5.4Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
CVE-2020-27989MEDIUM5.4Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
CVE-2020-27988MEDIUM5.4Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
CVE-2020-27627MEDIUM6.1JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
CVE-2020-27623HIGH7.5JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
CVE-2020-27622MEDIUM5.3In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
CVE-2020-27423HIGH7.5Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial o...
CVE-2020-27422CRITICAL9.8In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an a...
CVE-2020-27191HIGH7.5LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the ind...
CVE-2020-26129MEDIUM6.5In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
CVE-2020-25952CRITICAL9.8SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allo...
CVE-2020-13773MEDIUM5.4Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_spli...
CVE-2020-13772MEDIUM5.3In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now