2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12102 | HIGH | 7.7 | 1.8% | Apr 28, 2020 | In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionalit... |
| CVE-2020-10663 | HIGH | 7.5 | 6.8% | Apr 28, 2020 | The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an... |
| CVE-2020-7451 | MEDIUM | 5.3 | 1.1% | Apr 28, 2020 | In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE... |
| CVE-2020-12430 | MEDIUM | 6.5 | 2.3% | Apr 28, 2020 | An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A... |
| CVE-2020-12429 | CRITICAL | 9.8 | 2.4% | Apr 28, 2020 | Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and aut... |
| CVE-2020-11014 | HIGH | 8.6 | 1.6% | Apr 28, 2020 | Electron-Cash-SLP before version 3.6.2 has a vulnerability. All token creators that use the "Mint Tool" feature of the E... |
| CVE-2020-9482 | MEDIUM | 6.5 | 2.6% | Apr 28, 2020 | If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Regi... |
| CVE-2020-7644 | HIGH | 8.1 | 1.2% | Apr 28, 2020 | fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modify... |
| CVE-2020-12243 | HIGH | 7.5 | 4.4% | Apr 28, 2020 | In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial... |
| CVE-2020-10641 | HIGH | 7.5 | 1.3% | Apr 28, 2020 | An unprotected logging route may allow an attacker to write endless log statements into the database without space limit... |
| CVE-2020-1745 | CRITICAL | 9.8 | 4.8% | Apr 28, 2020 | A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in U... |
| CVE-2020-4329 | MEDIUM | 4.3 | 1.3% | Apr 28, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenti... |
| CVE-2020-1774 | MEDIUM | 4.9 | 0.9% | Apr 28, 2020 | When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore ... |
| CVE-2020-12078 | HIGH | 8.8 | 10.0% | Apr 28, 2020 | An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/conf... |
| CVE-2020-10944 | MEDIUM | 5.4 | 0.7% | Apr 28, 2020 | HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a ... |
| CVE-2020-10094 | MEDIUM | 5.4 | 0.7% | Apr 28, 2020 | A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x befo... |
| CVE-2020-10093 | MEDIUM | 5.4 | 0.7% | Apr 28, 2020 | A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products. |
| CVE-2020-12286 | MEDIUM | 4.3 | 1.0% | Apr 28, 2020 | In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. Fo... |
| CVE-2020-5570 | MEDIUM | 5.4 | 0.8% | Apr 28, 2020 | Cross-site scripting vulnerability in Sales Force Assistant version 11.2.48 and earlier allows remote authenticated atta... |
| CVE-2020-12284 | CRITICAL | 9.8 | 3.8% | Apr 28, 2020 | cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MA... |
| CVE-2020-5568 | MEDIUM | 6.1 | 0.8% | Apr 28, 2020 | Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 5.0.0 allows remote attackers to inject arbitrary web scrip... |
| CVE-2020-5567 | HIGH | 7.5 | 1.4% | Apr 28, 2020 | Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in Applica... |
| CVE-2020-5566 | MEDIUM | 4.3 | 1.1% | Apr 28, 2020 | Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the... |
| CVE-2020-5565 | MEDIUM | 4.3 | 0.8% | Apr 28, 2020 | Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter... |
| CVE-2020-5564 | MEDIUM | 6.1 | 0.8% | Apr 28, 2020 | Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to inject arbitrary web scri... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now