2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-5299MEDIUM5.1In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to...
CVE-2020-5298MEDIUM4.8In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to us...
CVE-2020-5297LOW2.7In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this ...
CVE-2020-5296MEDIUM4.9In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this ...
CVE-2020-5295MEDIUM4.9In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this ...
CVE-2020-13798MEDIUM6.1An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/f...
CVE-2020-13797MEDIUM6.1An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/w...
CVE-2020-13796MEDIUM6.1An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/s...
CVE-2020-13795MEDIUM5.3An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/temp...
CVE-2020-13792MEDIUM4.3PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory tra...
CVE-2020-3353MEDIUM5.9A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, ...
CVE-2020-3339MEDIUM5.4A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote...
CVE-2020-13790HIGH8.1libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PP...
CVE-2020-13379HIGH8.2The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows ...
CVE-2020-7015MEDIUM5.4Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to ...
CVE-2020-7014HIGH8.8The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 cont...
CVE-2020-7013HIGH7.2Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privil...
CVE-2020-7012HIGH8.8Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authen...
CVE-2020-7011MEDIUM6.1Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the ...
CVE-2020-7010HIGH7.5Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an...
CVE-2020-3335MEDIUM5.5A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attac...
CVE-2020-3333MEDIUM5.3A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker...
CVE-2020-3281HIGH8.8A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authent...
CVE-2020-3267HIGH7.1A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated,...
CVE-2020-3258CRITICAL9.8Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now