2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24426LOW3.3Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) a...
CVE-2020-8267MEDIUM5.3A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect cont...
CVE-2020-13661HIGH8.8Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing sp...
CVE-2020-12147HIGH8.8In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unautho...
CVE-2020-12146HIGH8.8In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modi...
CVE-2020-12145CRITICAL9.8Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API...
CVE-2020-26507HIGH7.8A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 al...
CVE-2020-4097MEDIUM6.8In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack...
CVE-2020-26505MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an atta...
CVE-2020-14240MEDIUM6.1HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site ...
CVE-2020-14222MEDIUM6.1HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to ref...
CVE-2020-26506MEDIUM4.3An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower priv...
CVE-2020-25399HIGH7.8Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malic...
CVE-2020-25398HIGH8.8CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
CVE-2020-28115HIGH8.8SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arb...
CVE-2020-28047MEDIUM5.4AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration...
CVE-2020-27955CRITICAL9.8Git LFS 2.12.0 allows Remote Code Execution.
CVE-2020-27688HIGH7.5RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. ...
CVE-2020-27402HIGH7.8The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /...
CVE-2020-24849HIGH8.8A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metachara...
CVE-2020-15952CRITICAL9Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permi...
CVE-2020-15951MEDIUM6.1Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject ar...
CVE-2020-15950HIGH8.8Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
CVE-2020-15949HIGH7.5Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
CVE-2020-7763HIGH7.5This affects the package phantom-html-to-pdf before 0.6.1.

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now