2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-8185MEDIUM6.5A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations ...
CVE-2020-8179MEDIUM4.1Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
CVE-2020-8176MEDIUM6.1A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS pay...
CVE-2020-8166MEDIUM4.3A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a g...
CVE-2020-8163HIGH8.8The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the...
CVE-2020-8161HIGH8.6A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerabi...
CVE-2020-4074CRITICAL9.8In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is...
CVE-2020-4061MEDIUM5.4In October from version 1.0.319 and before version 1.0.467, pasting content copied from malicious websites into the Froa...
CVE-2020-15091MEDIUM6.5TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong bloc...
CVE-2020-15083MEDIUM6.1In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflect...
CVE-2020-15082HIGH8.8In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variable...
CVE-2020-15081MEDIUM5.3In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The proble...
CVE-2020-15080MEDIUM5.3In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and othe...
CVE-2020-15079MEDIUM5.4In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module ...
CVE-2020-11074MEDIUM5.4In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick acce...
CVE-2020-14092CRITICAL9.8The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
CVE-2020-13653MEDIUM6.1An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an ...
CVE-2020-2219MEDIUM5.4Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission...
CVE-2020-2218LOW3.3Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on t...
CVE-2020-2217MEDIUM6.1Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the t...
CVE-2020-2216MEDIUM4.3A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overa...
CVE-2020-2215MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows atta...
CVE-2020-2214MEDIUM5.4Jenkins ZAP Pipeline Plugin 1.9 and earlier programmatically disables Content-Security-Policy protection for user-genera...
CVE-2020-2213MEDIUM4.3Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in jo...
CVE-2020-2212MEDIUM4.3Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on t...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now