2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-28644 | MEDIUM | 4.3 | 0.5% | Feb 9, 2021 | The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against so... |
| CVE-2020-35943 | MEDIUM | 6.5 | 0.7% | Feb 9, 2021 | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (... |
| CVE-2020-35572 | MEDIUM | 6.1 | 2.0% | Feb 9, 2021 | Adminer through 4.7.8 allows XSS via the history parameter to the default URI. |
| CVE-2020-28394 | MEDIUM | 5.5 | 0.7% | Feb 9, 2021 | A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.... |
| CVE-2020-28388 | MEDIUM | 5.3 | 1.6% | Feb 9, 2021 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ether... |
| CVE-2020-16144 | MEDIUM | 5.7 | 0.8% | Feb 9, 2021 | When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous us... |
| CVE-2020-27008 | MEDIUM | 5.5 | 0.7% | Feb 9, 2021 | A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.... |
| CVE-2020-27007 | MEDIUM | 5.5 | 2.5% | Feb 9, 2021 | A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.... |
| CVE-2020-27004 | MEDIUM | 5.5 | 2.0% | Feb 9, 2021 | A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.... |
| CVE-2020-26998 | MEDIUM | 5.5 | 0.6% | Feb 9, 2021 | A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.... |
| CVE-2020-10048 | MEDIUM | 5.5 | 0.3% | Feb 9, 2021 | A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an ... |
| CVE-2020-4996 | MEDIUM | 5.5 | 0.4% | Feb 9, 2021 | IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the... |
| CVE-2020-4995 | MEDIUM | 5.3 | 1.1% | Feb 9, 2021 | IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a use... |
| CVE-2020-4791 | MEDIUM | 5.3 | 0.3% | Feb 9, 2021 | IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using ma... |
| CVE-2020-4790 | MEDIUM | 6.5 | 0.6% | Feb 9, 2021 | IBM Security Identity Governance and Intelligence 5.2.6 could allow a user to cause a denial of service due to improperl... |
| CVE-2020-22841 | MEDIUM | 4.8 | 3.5% | Feb 9, 2021 | Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution... |
| CVE-2020-22840 | MEDIUM | 6.1 | 13.9% | Feb 9, 2021 | Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redi... |
| CVE-2020-13462 | MEDIUM | 5.7 | 0.4% | Feb 9, 2021 | Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in... |
| CVE-2020-13461 | MEDIUM | 4.3 | 0.5% | Feb 9, 2021 | Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided... |
| CVE-2020-13409 | MEDIUM | 5.9 | 0.4% | Feb 9, 2021 | Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als... |
| CVE-2020-13408 | MEDIUM | 5.9 | 0.4% | Feb 9, 2021 | Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als... |
| CVE-2020-13407 | MEDIUM | 5.9 | 0.4% | Feb 9, 2021 | Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is als... |
| CVE-2020-29021 | MEDIUM | 4.8 | 0.6% | Feb 8, 2021 | A vulnerability in web UI input field of GateManager allows authenticated attacker to enter script tags that could cause... |
| CVE-2020-14391 | MEDIUM | 5.5 | 0.3% | Feb 8, 2021 | A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly us... |
| CVE-2020-8587 | MEDIUM | 5.5 | 0.4% | Feb 8, 2021 | OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that cou... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now