2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-8185 | MEDIUM | 6.5 | 2.2% | Jul 2, 2020 | A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations ... |
| CVE-2020-8179 | MEDIUM | 4.1 | 0.6% | Jul 2, 2020 | Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks. |
| CVE-2020-8176 | MEDIUM | 6.1 | 1.0% | Jul 2, 2020 | A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS pay... |
| CVE-2020-8166 | MEDIUM | 4.3 | 1.7% | Jul 2, 2020 | A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a g... |
| CVE-2020-8163 | HIGH | 8.8 | 83.1% | Jul 2, 2020 | The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the... |
| CVE-2020-8161 | HIGH | 8.6 | 3.6% | Jul 2, 2020 | A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerabi... |
| CVE-2020-4074 | CRITICAL | 9.8 | 1.8% | Jul 2, 2020 | In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is... |
| CVE-2020-4061 | MEDIUM | 5.4 | 0.8% | Jul 2, 2020 | In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froa... |
| CVE-2020-15091 | MEDIUM | 6.5 | 0.9% | Jul 2, 2020 | TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong bloc... |
| CVE-2020-15083 | MEDIUM | 6.1 | 0.7% | Jul 2, 2020 | In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflect... |
| CVE-2020-15082 | HIGH | 8.8 | 1.2% | Jul 2, 2020 | In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variable... |
| CVE-2020-15081 | MEDIUM | 5.3 | 1.6% | Jul 2, 2020 | In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The proble... |
| CVE-2020-15080 | MEDIUM | 5.3 | 0.9% | Jul 2, 2020 | In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and othe... |
| CVE-2020-15079 | MEDIUM | 5.4 | 0.6% | Jul 2, 2020 | In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module ... |
| CVE-2020-11074 | MEDIUM | 5.4 | 0.6% | Jul 2, 2020 | In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick acce... |
| CVE-2020-14092 | CRITICAL | 9.8 | 94.5% | Jul 2, 2020 | The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection. |
| CVE-2020-13653 | MEDIUM | 6.1 | 1.4% | Jul 2, 2020 | An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an ... |
| CVE-2020-2219 | MEDIUM | 5.4 | 0.7% | Jul 2, 2020 | Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission... |
| CVE-2020-2218 | LOW | 3.3 | 0.3% | Jul 2, 2020 | Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on t... |
| CVE-2020-2217 | MEDIUM | 6.1 | 0.7% | Jul 2, 2020 | Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the t... |
| CVE-2020-2216 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overa... |
| CVE-2020-2215 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows atta... |
| CVE-2020-2214 | MEDIUM | 5.4 | 0.7% | Jul 2, 2020 | Jenkins ZAP Pipeline Plugin 1.9 and earlier programmatically disables Content-Security-Policy protection for user-genera... |
| CVE-2020-2213 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in jo... |
| CVE-2020-2212 | MEDIUM | 4.3 | 0.7% | Jul 2, 2020 | Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on t... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now