2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-13769HIGH8.8LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device r...
CVE-2020-27629MEDIUM5.3In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there a...
CVE-2020-27628MEDIUM4.3In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
CVE-2020-27626MEDIUM5.3JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
CVE-2020-27625MEDIUM5.3In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
CVE-2020-27624MEDIUM5.3JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
CVE-2020-27459MEDIUM6.1Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the...
CVE-2020-25210MEDIUM5.3In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.
CVE-2020-25209HIGH7.5In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure ...
CVE-2020-25207CRITICAL9.8JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
CVE-2020-25013HIGH7.5JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
CVE-2020-24366LOW3.3Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via applicati...
CVE-2020-8897HIGH8.1A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2...
CVE-2020-7773MEDIUM6.1This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of ...
CVE-2020-7765MEDIUM5.3This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the D...
CVE-2020-5664CRITICAL9.8Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary...
CVE-2020-5663MEDIUM5.4Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject ar...
CVE-2020-5662MEDIUM5.4Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject...
CVE-2020-5659HIGH8.8SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary S...
CVE-2020-28656MEDIUM6.8The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically pr...
CVE-2020-28650MEDIUM5.4The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard W...
CVE-2020-28649HIGH8.8The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file...
CVE-2020-28648HIGH8.8Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to ...
CVE-2020-28642CRITICAL9.8In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it ea...
CVE-2020-8273HIGH8.8Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now