2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2182MEDIUM4.3Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$...
CVE-2020-2181MEDIUM6.5Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build lo...
CVE-2020-12672HIGH7.5GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
CVE-2020-12666MEDIUM6.1macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.c...
CVE-2020-12463HIGH7.8An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling f...
CVE-2020-12439MEDIUM5.3Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.
CVE-2020-11036MEDIUM5.4In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored ...
CVE-2020-11035CRITICAL9.3In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The im...
CVE-2020-11034MEDIUM6.1In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is...
CVE-2020-11033HIGH7.2In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to ful...
CVE-2020-11051MEDIUM4.8In Wiki.js before 2.3.81, there is a stored XSS in the Markdown editor. An editor with write access to a page, using the...
CVE-2020-11032HIGH7.2In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnera...
CVE-2020-10859MEDIUM6.5Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extracti...
CVE-2020-10634CRITICAL9.1SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file s...
CVE-2020-10630MEDIUM6.1SAE IT-systems FW-50 Remote Telemetry Unit (RTU). The software does not neutralize or incorrectly neutralizes user-contr...
CVE-2020-12144MEDIUM4.9The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it pos...
CVE-2020-12143MEDIUM4.9The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someo...
CVE-2020-12142MEDIUM4.91. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user ...
CVE-2020-11495Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2020-8830HIGH8.8CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other an...
CVE-2020-8829HIGH8.8CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.
CVE-2020-8033MEDIUM6.1Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.
CVE-2020-7983HIGH8.1A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF...
CVE-2020-5517MEDIUM6.5CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analys...
CVE-2020-8799MEDIUM4.8A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordP...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now