2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-15668MEDIUM4.3A lock was missing when accessing a data structure and importing certificate information into the trust database. This v...
CVE-2020-15667HIGH8.8When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap...
CVE-2020-15666MEDIUM6.5When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was...
CVE-2020-15665MEDIUM4.3Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. T...
CVE-2020-15664MEDIUM6.5By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access t...
CVE-2020-15663HIGH8.8If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the...
CVE-2020-15533CRITICAL9.8In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalati...
CVE-2020-15227CRITICAL9.8Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passin...
CVE-2020-25200MEDIUM5.3Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Ini...
CVE-2020-15228MEDIUM5In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Act...
CVE-2020-25018HIGH7.5Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.
CVE-2020-25017HIGH8.3Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy...
CVE-2020-24620HIGH7.8Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager ...
CVE-2020-16844MEDIUM6.8In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY ...
CVE-2020-4576HIGH7.5IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive in...
CVE-2020-25990CRITICAL9.8WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Explo...
CVE-2020-24861MEDIUM5.4GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is execu...
CVE-2020-24860MEDIUM5.4CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persisten...
CVE-2020-8109HIGH7.5A vulnerability has been discovered in the ace.xmd parser that results from a lack of proper validation of user-supplied...
CVE-2020-6654HIGH7.8A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attac...
CVE-2020-26159Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Further investigation showed that it was not a secu...
CVE-2020-25830MEDIUM4.8An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inje...
CVE-2020-25781MEDIUM4.3An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes...
CVE-2020-25288MEDIUM4.8An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafte...
CVE-2020-16234HIGH7.8In PLC WinProladder Version 3.28 and prior, a stack-based buffer overflow vulnerability can be exploited when a valid us...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now