2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-12050HIGH7SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privile...
CVE-2020-11652MEDIUM6.5An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla...
CVE-2020-11651CRITICAL9.8An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla...
CVE-2020-10691MEDIUM5.2An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy col...
CVE-2020-6010HIGH8.8LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
CVE-2020-6579MEDIUM6.1Cross-site scripting (XSS) vulnerability in mailhive/cloudbeez/cloudloader.php and mailhive/cloudbeez/cloudloader_core.p...
CVE-2020-12101MEDIUM4.3The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's st...
CVE-2020-9387MEDIUM4.3In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for acc...
CVE-2020-12283MEDIUM6.1Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL...
CVE-2020-12479HIGH8.8TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP...
CVE-2020-12478HIGH7.5TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include bac...
CVE-2020-12477HIGH7.5The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restri...
CVE-2020-11943HIGH8.8An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
CVE-2020-11942CRITICAL9.8An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.
CVE-2020-11022MEDIUM6.1In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one...
CVE-2020-12471CRITICAL9.8MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGal...
CVE-2020-12470HIGH7.2MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
CVE-2020-12469MEDIUM6.5admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized ...
CVE-2020-12468HIGH7.8Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languag...
CVE-2020-12467MEDIUM6.5Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie.
CVE-2020-11024HIGH8.2In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack. The bug has been fi...
CVE-2020-11023MEDIUM6.1In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untru...
CVE-2020-12473HIGH7.2MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting ...
CVE-2020-12472MEDIUM5.4MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
CVE-2020-12465MEDIUM6.7An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel be...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now