2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7489CRITICAL9.8A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerabili...
CVE-2020-7488HIGH7.5A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information t...
CVE-2020-7487CRITICAL9.8A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute...
CVE-2020-7055CRITICAL9.9An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function...
CVE-2020-12066HIGH7.5CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the se...
CVE-2020-11011HIGH8.8In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arb...
CVE-2020-7642MEDIUM5.4lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the vide...
CVE-2020-5740HIGH7.8Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary ...
CVE-2020-10712HIGH8.2A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by ...
CVE-2020-8477HIGH8.8The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxil...
CVE-2020-8474HIGH7.8Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings relat...
CVE-2020-4085MEDIUM6.5"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace ...
CVE-2020-11938MEDIUM4.9In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters use...
CVE-2020-11796CRITICAL9.8In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
CVE-2020-11795HIGH7.5In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
CVE-2020-11693HIGH7.5JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an...
CVE-2020-11692LOW2.7In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
CVE-2020-11691HIGH7.5In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
CVE-2020-11690CRITICAL9.8In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
CVE-2020-11689MEDIUM6.5In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the setti...
CVE-2020-11688HIGH7.5In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
CVE-2020-11687HIGH7.5In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
CVE-2020-11686LOW2.7In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
CVE-2020-11685HIGH7.5In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
CVE-2020-11539HIGH8.1An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pai...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now