2020 CVE Vulnerabilities

21,071 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7746CRITICAL9.8This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. Wh...
CVE-2020-11616HIGH7.5NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which...
CVE-2020-11615HIGH7.5NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which...
CVE-2020-11489HIGH7.5NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior...
CVE-2020-11488MEDIUM6.7NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior...
CVE-2020-11487HIGH7.5NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06...
CVE-2020-11486CRITICAL9.8NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmwa...
CVE-2020-11485HIGH8.8NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) ...
CVE-2020-11484MEDIUM4.9NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmw...
CVE-2020-11483CRITICAL9.8NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior...
CVE-2020-27986HIGH7.5SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settin...
CVE-2020-27981Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-25374LOW2.6CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error ...
CVE-2020-24713HIGH7.5Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
CVE-2020-24712MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
CVE-2020-24711MEDIUM6.5The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via...
CVE-2020-24710MEDIUM5.3Gophish before 0.11.0 allows SSRF attacks.
CVE-2020-24709MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.
CVE-2020-24708MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
CVE-2020-24707HIGH7.8Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
CVE-2020-27980MEDIUM5.4Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to...
CVE-2020-27742MEDIUM6.5An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to...
CVE-2020-27741MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbit...
CVE-2020-27740MEDIUM5.3Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. NOTE: t...
CVE-2020-27739CRITICAL9.8A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now