2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25020CRITICAL9.8MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
CVE-2020-25019HIGH7.5jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verify...
CVE-2020-3566HIGH8.6A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow a...
CVE-2020-25016CRITICAL9.1A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arb...
CVE-2020-15159HIGH7.6baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be execut...
CVE-2020-15155HIGH7.3baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is req...
CVE-2020-15154HIGH7.3baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is req...
CVE-2020-15165CRITICAL9.1Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampere...
CVE-2020-16610MEDIUM4.3Hoosk Codeigniter CMS before 1.7.2 is affected by a Cross Site Request Forgery (CSRF). When an attacker induces authenti...
CVE-2020-15164CRITICAL10in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username wit...
CVE-2020-9298HIGH7.5The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an att...
CVE-2020-4591LOW3.3IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due...
CVE-2020-4559HIGH7.5IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user...
CVE-2020-5625MEDIUM6.1Cross-site scripting vulnerability in XooNIps 3.48 and earlier allows remote attackers to inject an arbitrary script via...
CVE-2020-5624CRITICAL9.8SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands vi...
CVE-2020-5623MEDIUM6.1NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attacke...
CVE-2020-5621MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlie...
CVE-2020-24715CRITICAL9.8The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code...
CVE-2020-24714CRITICAL9.8The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary...
CVE-2020-10518HIGH8.8A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a...
CVE-2020-10517MEDIUM4.3An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of ...
CVE-2020-8602HIGH7.2A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protecti...
CVE-2020-15605HIGH8.1If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2...
CVE-2020-15601HIGH8.1If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x co...
CVE-2020-24618MEDIUM6.5In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now