2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-14015HIGH7.5An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation cod...
CVE-2020-14014MEDIUM5.4An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not...
CVE-2020-13700HIGH7.5An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object r...
CVE-2020-13484CRITICAL9.8Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview u...
CVE-2020-13483MEDIUM6.1The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/...
CVE-2020-13443HIGH8.8ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose...
CVE-2020-4413MEDIUM5.9IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to ...
CVE-2020-4342MEDIUM5.3IBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized u...
CVE-2020-4341MEDIUM5.3IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical ...
CVE-2020-4327MEDIUM5.3IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical ...
CVE-2020-4323MEDIUM6.1IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2020-4322MEDIUM4.3IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading...
CVE-2020-14007MEDIUM5.4Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an a...
CVE-2020-14006MEDIUM5.4Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible ...
CVE-2020-14005HIGH8.8Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to ex...
CVE-2020-4071LOW2.4In django-basic-auth-ip-whitelist before 0.3.4, a potential timing attack exists on websites where the basic authenticat...
CVE-2020-15018MEDIUM6.5playSMS through 1.4.3 is vulnerable to session fixation.
CVE-2020-15014HIGH8.8pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.
CVE-2020-12866MEDIUM5.7A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network ...
CVE-2020-12865HIGH8A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network a...
CVE-2020-12864MEDIUM4.3An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as...
CVE-2020-12863MEDIUM4.3An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as...
CVE-2020-12862MEDIUM4.3An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as...
CVE-2020-12861HIGH8.8A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as t...
CVE-2020-7667HIGH7.5In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanit...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now