2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2182 | MEDIUM | 4.3 | 0.9% | May 6, 2020 | Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$... |
| CVE-2020-2181 | MEDIUM | 6.5 | 1.1% | May 6, 2020 | Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build lo... |
| CVE-2020-12672 | HIGH | 7.5 | 2.9% | May 6, 2020 | GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c. |
| CVE-2020-12666 | MEDIUM | 6.1 | 1.4% | May 5, 2020 | macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.c... |
| CVE-2020-12463 | HIGH | 7.8 | 0.4% | May 5, 2020 | An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling f... |
| CVE-2020-12439 | MEDIUM | 5.3 | 1.6% | May 5, 2020 | Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain. |
| CVE-2020-11036 | MEDIUM | 5.4 | 0.8% | May 5, 2020 | In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored ... |
| CVE-2020-11035 | CRITICAL | 9.3 | 0.8% | May 5, 2020 | In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The im... |
| CVE-2020-11034 | MEDIUM | 6.1 | 7.6% | May 5, 2020 | In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is... |
| CVE-2020-11033 | HIGH | 7.2 | 1.0% | May 5, 2020 | In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to ful... |
| CVE-2020-11051 | MEDIUM | 4.8 | 0.6% | May 5, 2020 | In Wiki.js before 2.3.81, there is a stored XSS in the Markdown editor. An editor with write access to a page, using the... |
| CVE-2020-11032 | HIGH | 7.2 | 1.0% | May 5, 2020 | In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnera... |
| CVE-2020-10859 | MEDIUM | 6.5 | 4.4% | May 5, 2020 | Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extracti... |
| CVE-2020-10634 | CRITICAL | 9.1 | 1.4% | May 5, 2020 | SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file s... |
| CVE-2020-10630 | MEDIUM | 6.1 | 0.7% | May 5, 2020 | SAE IT-systems FW-50 Remote Telemetry Unit (RTU). The software does not neutralize or incorrectly neutralizes user-contr... |
| CVE-2020-12144 | MEDIUM | 4.9 | 0.3% | May 5, 2020 | The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it pos... |
| CVE-2020-12143 | MEDIUM | 4.9 | 0.3% | May 5, 2020 | The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someo... |
| CVE-2020-12142 | MEDIUM | 4.9 | 0.7% | May 5, 2020 | 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user ... |
| CVE-2020-11495 | — | — | — | May 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2020-8830 | HIGH | 8.8 | 0.5% | May 5, 2020 | CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other an... |
| CVE-2020-8829 | HIGH | 8.8 | 0.5% | May 5, 2020 | CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis. |
| CVE-2020-8033 | MEDIUM | 6.1 | 0.7% | May 5, 2020 | Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field. |
| CVE-2020-7983 | HIGH | 8.1 | 0.6% | May 5, 2020 | A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF... |
| CVE-2020-5517 | MEDIUM | 6.5 | 0.6% | May 5, 2020 | CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analys... |
| CVE-2020-8799 | MEDIUM | 4.8 | 0.7% | May 5, 2020 | A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordP... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now