2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4700 | HIGH | 8.8 | 1.2% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenti... |
| CVE-2020-4692 | MEDIUM | 6.5 | 0.9% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 could allow an authenti... |
| CVE-2020-4672 | MEDIUM | 5.4 | 0.6% | Nov 16, 2020 | IBM Business Automation Workflow 20.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2020-4671 | MEDIUM | 6.5 | 1.0% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sens... |
| CVE-2020-4665 | MEDIUM | 4.3 | 1.0% | Nov 16, 2020 | IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on autho... |
| CVE-2020-4655 | HIGH | 8.8 | 1.3% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL in... |
| CVE-2020-4647 | HIGH | 8.8 | 1.0% | Nov 16, 2020 | IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote a... |
| CVE-2020-4566 | MEDIUM | 6.5 | 1.0% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 stores potentially high... |
| CVE-2020-4476 | HIGH | 7.5 | 1.5% | Nov 16, 2020 | IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote attacker to obtain se... |
| CVE-2020-4475 | MEDIUM | 6.5 | 1.1% | Nov 16, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.2 could allow a remote at... |
| CVE-2020-28723 | HIGH | 7.5 | 1.6% | Nov 16, 2020 | Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1. |
| CVE-2020-27991 | MEDIUM | 5.4 | 21.7% | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field). |
| CVE-2020-27990 | MEDIUM | 5.4 | 21.7% | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent). |
| CVE-2020-27989 | MEDIUM | 5.4 | 21.7% | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard). |
| CVE-2020-27988 | MEDIUM | 5.4 | 87.2% | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field). |
| CVE-2020-27627 | MEDIUM | 6.1 | 0.7% | Nov 16, 2020 | JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection. |
| CVE-2020-27623 | HIGH | 7.5 | 1.1% | Nov 16, 2020 | JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances. |
| CVE-2020-27622 | MEDIUM | 5.3 | 1.3% | Nov 16, 2020 | In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version. |
| CVE-2020-27423 | HIGH | 7.5 | 6.4% | Nov 16, 2020 | Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial o... |
| CVE-2020-27422 | CRITICAL | 9.8 | 7.8% | Nov 16, 2020 | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an a... |
| CVE-2020-27191 | HIGH | 7.5 | 8.4% | Nov 16, 2020 | LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the ind... |
| CVE-2020-26129 | MEDIUM | 6.5 | 0.8% | Nov 16, 2020 | In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible. |
| CVE-2020-25952 | CRITICAL | 9.8 | 4.1% | Nov 16, 2020 | SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allo... |
| CVE-2020-13773 | MEDIUM | 5.4 | 1.3% | Nov 16, 2020 | Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_spli... |
| CVE-2020-13772 | MEDIUM | 5.3 | 2.3% | Nov 16, 2020 | In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now