2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12050 | HIGH | 7 | 0.3% | Apr 30, 2020 | SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privile... |
| CVE-2020-11652 | MEDIUM | 6.5 | 86.1% | Apr 30, 2020 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla... |
| CVE-2020-11651 | CRITICAL | 9.8 | 96.4% | Apr 30, 2020 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla... |
| CVE-2020-10691 | MEDIUM | 5.2 | 0.4% | Apr 30, 2020 | An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy col... |
| CVE-2020-6010 | HIGH | 8.8 | 49.2% | Apr 30, 2020 | LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection |
| CVE-2020-6579 | MEDIUM | 6.1 | 0.8% | Apr 30, 2020 | Cross-site scripting (XSS) vulnerability in mailhive/cloudbeez/cloudloader.php and mailhive/cloudbeez/cloudloader_core.p... |
| CVE-2020-12101 | MEDIUM | 4.3 | 2.0% | Apr 30, 2020 | The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's st... |
| CVE-2020-9387 | MEDIUM | 4.3 | 0.7% | Apr 30, 2020 | In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for acc... |
| CVE-2020-12283 | MEDIUM | 6.1 | 1.3% | Apr 30, 2020 | Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL... |
| CVE-2020-12479 | HIGH | 8.8 | 2.6% | Apr 29, 2020 | TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP... |
| CVE-2020-12478 | HIGH | 7.5 | 7.2% | Apr 29, 2020 | TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include bac... |
| CVE-2020-12477 | HIGH | 7.5 | 1.8% | Apr 29, 2020 | The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restri... |
| CVE-2020-11943 | HIGH | 8.8 | 23.9% | Apr 29, 2020 | An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload. |
| CVE-2020-11942 | CRITICAL | 9.8 | 1.2% | Apr 29, 2020 | An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections. |
| CVE-2020-11022 | MEDIUM | 6.1 | 99.0% | Apr 29, 2020 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one... |
| CVE-2020-12471 | CRITICAL | 9.8 | 2.8% | Apr 29, 2020 | MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGal... |
| CVE-2020-12470 | HIGH | 7.2 | 1.7% | Apr 29, 2020 | MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template. |
| CVE-2020-12469 | MEDIUM | 6.5 | 0.9% | Apr 29, 2020 | admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized ... |
| CVE-2020-12468 | HIGH | 7.8 | 0.9% | Apr 29, 2020 | Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languag... |
| CVE-2020-12467 | MEDIUM | 6.5 | 0.9% | Apr 29, 2020 | Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie. |
| CVE-2020-11024 | HIGH | 8.2 | 0.8% | Apr 29, 2020 | In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack. The bug has been fi... |
| CVE-2020-11023 | MEDIUM | 6.1 | 83.8% | Apr 29, 2020 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untru... |
| CVE-2020-12473 | HIGH | 7.2 | 1.4% | Apr 29, 2020 | MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting ... |
| CVE-2020-12472 | MEDIUM | 5.4 | 0.5% | Apr 29, 2020 | MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description. |
| CVE-2020-12465 | MEDIUM | 6.7 | 0.4% | Apr 29, 2020 | An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel be... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now