2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-7489 | CRITICAL | 9.8 | 1.5% | Apr 22, 2020 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerabili... |
| CVE-2020-7488 | HIGH | 7.5 | 0.8% | Apr 22, 2020 | A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information t... |
| CVE-2020-7487 | CRITICAL | 9.8 | 0.7% | Apr 22, 2020 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute... |
| CVE-2020-7055 | CRITICAL | 9.9 | 3.1% | Apr 22, 2020 | An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function... |
| CVE-2020-12066 | HIGH | 7.5 | 3.0% | Apr 22, 2020 | CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the se... |
| CVE-2020-11011 | HIGH | 8.8 | 1.9% | Apr 22, 2020 | In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arb... |
| CVE-2020-7642 | MEDIUM | 5.4 | 0.9% | Apr 22, 2020 | lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the vide... |
| CVE-2020-5740 | HIGH | 7.8 | 0.7% | Apr 22, 2020 | Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary ... |
| CVE-2020-10712 | HIGH | 8.2 | 1.0% | Apr 22, 2020 | A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by ... |
| CVE-2020-8477 | HIGH | 8.8 | 1.7% | Apr 22, 2020 | The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxil... |
| CVE-2020-8474 | HIGH | 7.8 | 0.3% | Apr 22, 2020 | Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings relat... |
| CVE-2020-4085 | MEDIUM | 6.5 | 0.8% | Apr 22, 2020 | "HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace ... |
| CVE-2020-11938 | MEDIUM | 4.9 | 0.9% | Apr 22, 2020 | In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters use... |
| CVE-2020-11796 | CRITICAL | 9.8 | 1.2% | Apr 22, 2020 | In JetBrains Space through 2020-04-22, the password authentication implementation was insecure. |
| CVE-2020-11795 | HIGH | 7.5 | 0.8% | Apr 22, 2020 | In JetBrains Space through 2020-04-22, the session timeout period was configured improperly. |
| CVE-2020-11693 | HIGH | 7.5 | 1.7% | Apr 22, 2020 | JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an... |
| CVE-2020-11692 | LOW | 2.7 | 0.9% | Apr 22, 2020 | In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators. |
| CVE-2020-11691 | HIGH | 7.5 | 0.9% | Apr 22, 2020 | In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible. |
| CVE-2020-11690 | CRITICAL | 9.8 | 2.2% | Apr 22, 2020 | In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases. |
| CVE-2020-11689 | MEDIUM | 6.5 | 0.6% | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the setti... |
| CVE-2020-11688 | HIGH | 7.5 | 1.0% | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session. |
| CVE-2020-11687 | HIGH | 7.5 | 1.1% | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages. |
| CVE-2020-11686 | LOW | 2.7 | 0.7% | Apr 22, 2020 | In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings. |
| CVE-2020-11685 | HIGH | 7.5 | 0.9% | Apr 22, 2020 | In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. |
| CVE-2020-11539 | HIGH | 8.1 | 1.0% | Apr 22, 2020 | An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pai... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now