2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4866 | MEDIUM | 5.4 | 0.5% | Mar 4, 2021 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
| CVE-2020-4863 | MEDIUM | 5.4 | 0.5% | Mar 4, 2021 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-4857 | MEDIUM | 5.4 | 0.7% | Mar 4, 2021 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-4856 | MEDIUM | 5.4 | 0.5% | Mar 4, 2021 | IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2020-35329 | MEDIUM | 6.5 | 1.3% | Mar 4, 2021 | Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '. |
| CVE-2020-35328 | MEDIUM | 5.4 | 0.7% | Mar 4, 2021 | Courier Management System 1.0 - 'First Name' Stored XSS |
| CVE-2020-35327 | MEDIUM | 6.5 | 1.3% | Mar 4, 2021 | SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST... |
| CVE-2020-24912 | MEDIUM | 6.1 | 6.3% | Mar 4, 2021 | A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQ... |
| CVE-2020-8296 | MEDIUM | 6.7 | 0.5% | Mar 3, 2021 | Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured. |
| CVE-2020-28591 | MEDIUM | 6.5 | 1.9% | Mar 3, 2021 | An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libsli... |
| CVE-2020-27749 | MEDIUM | 6.7 | 0.6% | Mar 3, 2021 | A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line in... |
| CVE-2020-15937 | MEDIUM | 6.1 | 0.8% | Mar 3, 2021 | An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow... |
| CVE-2020-12530 | MEDIUM | 6.1 | 0.6% | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There ... |
| CVE-2020-12529 | MEDIUM | 5.3 | 0.8% | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There i... |
| CVE-2020-12527 | MEDIUM | 6.5 | 1.0% | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all ve... |
| CVE-2020-4719 | MEDIUM | 4.9 | 0.8% | Mar 2, 2021 | The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management ... |
| CVE-2020-23518 | MEDIUM | 5.4 | 2.0% | Mar 2, 2021 | Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to vers... |
| CVE-2020-25902 | MEDIUM | 6.1 | 0.7% | Mar 2, 2021 | Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execu... |
| CVE-2020-1936 | MEDIUM | 6.1 | 2.9% | Mar 2, 2021 | A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4. |
| CVE-2020-36240 | MEDIUM | 5.3 | 1.2% | Mar 1, 2021 | The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthe... |
| CVE-2020-9479 | MEDIUM | 5.5 | 2.0% | Mar 1, 2021 | When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory.... |
| CVE-2020-7929 | MEDIUM | 6.5 | 1.3% | Mar 1, 2021 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a... |
| CVE-2020-28972 | MEDIUM | 5.9 | 3.1% | Feb 27, 2021 | In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) do... |
| CVE-2020-27618 | MEDIUM | 5.5 | 0.9% | Feb 26, 2021 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input ... |
| CVE-2020-27223 | MEDIUM | 5.3 | 78.0% | Feb 26, 2021 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request contai... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now