2020 CVE Vulnerabilities
21,074 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-14015 | HIGH | 7.5 | 1.4% | Jun 24, 2020 | An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation cod... |
| CVE-2020-14014 | MEDIUM | 5.4 | 0.6% | Jun 24, 2020 | An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not... |
| CVE-2020-13700 | HIGH | 7.5 | 13.0% | Jun 24, 2020 | An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object r... |
| CVE-2020-13484 | CRITICAL | 9.8 | 2.0% | Jun 24, 2020 | Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview u... |
| CVE-2020-13483 | MEDIUM | 6.1 | 4.5% | Jun 24, 2020 | The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/... |
| CVE-2020-13443 | HIGH | 8.8 | 4.3% | Jun 24, 2020 | ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose... |
| CVE-2020-4413 | MEDIUM | 5.9 | 1.2% | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to ... |
| CVE-2020-4342 | MEDIUM | 5.3 | 1.1% | Jun 24, 2020 | IBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized u... |
| CVE-2020-4341 | MEDIUM | 5.3 | 1.4% | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical ... |
| CVE-2020-4327 | MEDIUM | 5.3 | 1.1% | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical ... |
| CVE-2020-4323 | MEDIUM | 6.1 | 0.7% | Jun 24, 2020 | IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2020-4322 | MEDIUM | 4.3 | 1.0% | Jun 24, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading... |
| CVE-2020-14007 | MEDIUM | 5.4 | 1.1% | Jun 24, 2020 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an a... |
| CVE-2020-14006 | MEDIUM | 5.4 | 1.1% | Jun 24, 2020 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible ... |
| CVE-2020-14005 | HIGH | 8.8 | 14.3% | Jun 24, 2020 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to ex... |
| CVE-2020-4071 | LOW | 2.4 | 0.4% | Jun 24, 2020 | In django-basic-auth-ip-whitelist before 0.3.4, a potential timing attack exists on websites where the basic authenticat... |
| CVE-2020-15018 | MEDIUM | 6.5 | 0.9% | Jun 24, 2020 | playSMS through 1.4.3 is vulnerable to session fixation. |
| CVE-2020-15014 | HIGH | 8.8 | 0.5% | Jun 24, 2020 | pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF. |
| CVE-2020-12866 | MEDIUM | 5.7 | 1.0% | Jun 24, 2020 | A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network ... |
| CVE-2020-12865 | HIGH | 8 | 1.5% | Jun 24, 2020 | A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network a... |
| CVE-2020-12864 | MEDIUM | 4.3 | 1.2% | Jun 24, 2020 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as... |
| CVE-2020-12863 | MEDIUM | 4.3 | 1.0% | Jun 24, 2020 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as... |
| CVE-2020-12862 | MEDIUM | 4.3 | 1.1% | Jun 24, 2020 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as... |
| CVE-2020-12861 | HIGH | 8.8 | 3.0% | Jun 24, 2020 | A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as t... |
| CVE-2020-7667 | HIGH | 7.5 | 1.6% | Jun 24, 2020 | In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanit... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now