2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-5299 | MEDIUM | 5.1 | 1.0% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to... |
| CVE-2020-5298 | MEDIUM | 4.8 | 0.9% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to us... |
| CVE-2020-5297 | LOW | 2.7 | 1.2% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this ... |
| CVE-2020-5296 | MEDIUM | 4.9 | 1.4% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this ... |
| CVE-2020-5295 | MEDIUM | 4.9 | 7.4% | Jun 3, 2020 | In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this ... |
| CVE-2020-13798 | MEDIUM | 6.1 | 0.7% | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/f... |
| CVE-2020-13797 | MEDIUM | 6.1 | 0.7% | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/w... |
| CVE-2020-13796 | MEDIUM | 6.1 | 0.7% | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/s... |
| CVE-2020-13795 | MEDIUM | 5.3 | 1.8% | Jun 3, 2020 | An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/temp... |
| CVE-2020-13792 | MEDIUM | 4.3 | 1.1% | Jun 3, 2020 | PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory tra... |
| CVE-2020-3353 | MEDIUM | 5.9 | 0.8% | Jun 3, 2020 | A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, ... |
| CVE-2020-3339 | MEDIUM | 5.4 | 1.1% | Jun 3, 2020 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote... |
| CVE-2020-13790 | HIGH | 8.1 | 3.2% | Jun 3, 2020 | libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PP... |
| CVE-2020-13379 | HIGH | 8.2 | 99.9% | Jun 3, 2020 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows ... |
| CVE-2020-7015 | MEDIUM | 5.4 | 0.8% | Jun 3, 2020 | Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to ... |
| CVE-2020-7014 | HIGH | 8.8 | 1.5% | Jun 3, 2020 | The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 cont... |
| CVE-2020-7013 | HIGH | 7.2 | 2.1% | Jun 3, 2020 | Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privil... |
| CVE-2020-7012 | HIGH | 8.8 | 18.2% | Jun 3, 2020 | Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authen... |
| CVE-2020-7011 | MEDIUM | 6.1 | 1.0% | Jun 3, 2020 | Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the ... |
| CVE-2020-7010 | HIGH | 7.5 | 1.4% | Jun 3, 2020 | Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an... |
| CVE-2020-3335 | MEDIUM | 5.5 | 0.3% | Jun 3, 2020 | A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attac... |
| CVE-2020-3333 | MEDIUM | 5.3 | 1.0% | Jun 3, 2020 | A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker... |
| CVE-2020-3281 | HIGH | 8.8 | 1.0% | Jun 3, 2020 | A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authent... |
| CVE-2020-3267 | HIGH | 7.1 | 0.8% | Jun 3, 2020 | A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated,... |
| CVE-2020-3258 | CRITICAL | 9.8 | 4.6% | Jun 3, 2020 | Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now