2020 CVE Vulnerabilities
21,070 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-13769 | HIGH | 8.8 | 2.6% | Nov 16, 2020 | LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device r... |
| CVE-2020-27629 | MEDIUM | 5.3 | 0.9% | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there a... |
| CVE-2020-27628 | MEDIUM | 4.3 | 0.7% | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records. |
| CVE-2020-27626 | MEDIUM | 5.3 | 1.3% | Nov 16, 2020 | JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF. |
| CVE-2020-27625 | MEDIUM | 5.3 | 1.4% | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues. |
| CVE-2020-27624 | MEDIUM | 5.3 | 1.4% | Nov 16, 2020 | JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. |
| CVE-2020-27459 | MEDIUM | 6.1 | 0.8% | Nov 16, 2020 | Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the... |
| CVE-2020-25210 | MEDIUM | 5.3 | 1.4% | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants. |
| CVE-2020-25209 | HIGH | 7.5 | 2.4% | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure ... |
| CVE-2020-25207 | CRITICAL | 9.8 | 4.4% | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler. |
| CVE-2020-25013 | HIGH | 7.5 | 1.4% | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler. |
| CVE-2020-24366 | LOW | 3.3 | 0.3% | Nov 16, 2020 | Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via applicati... |
| CVE-2020-8897 | HIGH | 8.1 | 0.4% | Nov 16, 2020 | A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2... |
| CVE-2020-7773 | MEDIUM | 6.1 | 1.3% | Nov 16, 2020 | This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of ... |
| CVE-2020-7765 | MEDIUM | 5.3 | 0.6% | Nov 16, 2020 | This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the D... |
| CVE-2020-5664 | CRITICAL | 9.8 | 2.6% | Nov 16, 2020 | Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary... |
| CVE-2020-5663 | MEDIUM | 5.4 | 0.7% | Nov 16, 2020 | Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject ar... |
| CVE-2020-5662 | MEDIUM | 5.4 | 0.8% | Nov 16, 2020 | Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject... |
| CVE-2020-5659 | HIGH | 8.8 | 1.1% | Nov 16, 2020 | SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary S... |
| CVE-2020-28656 | MEDIUM | 6.8 | 0.3% | Nov 16, 2020 | The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically pr... |
| CVE-2020-28650 | MEDIUM | 5.4 | 0.7% | Nov 16, 2020 | The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard W... |
| CVE-2020-28649 | HIGH | 8.8 | 0.8% | Nov 16, 2020 | The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file... |
| CVE-2020-28648 | HIGH | 8.8 | 6.1% | Nov 16, 2020 | Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to ... |
| CVE-2020-28642 | CRITICAL | 9.8 | 2.5% | Nov 16, 2020 | In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it ea... |
| CVE-2020-8273 | HIGH | 8.8 | 2.4% | Nov 16, 2020 | Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now