2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-4281MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerabi...
CVE-2020-14470MEDIUM6.5In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that l...
CVE-2020-14460MEDIUM6.5An issue was discovered in Mattermost Server before 5.19.0, 5.18.1, 5.17.3, 5.16.5, and 5.9.8. Creation of a trusted OAu...
CVE-2020-14459HIGH7.5An issue was discovered in Mattermost Server before 5.19.0. Attackers can rename a channel and cause a collision with a ...
CVE-2020-14458HIGH7.5An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel...
CVE-2020-14457MEDIUM5.3An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the upd...
CVE-2020-14456HIGH7.3An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-contr...
CVE-2020-14455MEDIUM6.5An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, a...
CVE-2020-14454MEDIUM6.1An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application ...
CVE-2020-14453HIGH7.5An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, whi...
CVE-2020-14452MEDIUM5.3An issue was discovered in Mattermost Server before 5.21.0. mmctl allows directory traversal via HTTP, aka MMSA-2020-001...
CVE-2020-14451HIGH7.5An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local St...
CVE-2020-14450HIGH7.5An issue was discovered in Mattermost Server before 5.22.0. The markdown renderer allows attackers to cause a denial of ...
CVE-2020-14449HIGH7.5An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to thir...
CVE-2020-14448HIGH7.5An issue was discovered in Mattermost Server before 5.23.0. Automatic direct message replies allow attackers to cause a ...
CVE-2020-14447HIGH7.5An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of ...
CVE-2020-14462MEDIUM5.4CALDERA 2.7.0 allows XSS via the Operation Name box.
CVE-2020-7679CRITICAL9.8In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.
CVE-2020-14019HIGH7.8Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instea...
CVE-2020-5590HIGH8.1Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to...
CVE-2020-4059HIGH7.3In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a ...
CVE-2020-12887HIGH7.5Memory leaks were discovered in the CoAP library in Arm Mbed OS 5.15.3 when using the Arm mbed-coap library 5.1.5. The C...
CVE-2020-12886CRITICAL9.1A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing ...
CVE-2020-12885HIGH7.5An infinite loop was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing re...
CVE-2020-12884CRITICAL9.1A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now