2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4828 | MEDIUM | 6.5 | 0.8% | Feb 4, 2021 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to web cache poisoning, cause... |
| CVE-2020-4827 | MEDIUM | 4.3 | 0.4% | Feb 4, 2021 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery... |
| CVE-2020-4826 | MEDIUM | 4.3 | 0.4% | Feb 4, 2021 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery... |
| CVE-2020-4825 | MEDIUM | 5.4 | 0.7% | Feb 4, 2021 | IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This... |
| CVE-2020-4640 | MEDIUM | 4.1 | 0.3% | Feb 4, 2021 | Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensit... |
| CVE-2020-27873 | MEDIUM | 6.5 | 0.6% | Feb 4, 2021 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG... |
| CVE-2020-16194 | MEDIUM | 5.3 | 1.2% | Feb 4, 2021 | An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated at... |
| CVE-2020-14247 | MEDIUM | 6.5 | 0.7% | Feb 4, 2021 | HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to... |
| CVE-2020-9390 | MEDIUM | 5.4 | 0.9% | Feb 3, 2021 | SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content... |
| CVE-2020-9388 | MEDIUM | 6.5 | 0.8% | Feb 3, 2021 | CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administ... |
| CVE-2020-18724 | MEDIUM | 5.4 | 3.2% | Feb 3, 2021 | Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19... |
| CVE-2020-18723 | MEDIUM | 5.4 | 3.8% | Feb 3, 2021 | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code ... |
| CVE-2020-8294 | MEDIUM | 5.4 | 0.9% | Feb 3, 2021 | A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack usi... |
| CVE-2020-35482 | MEDIUM | 5.4 | 1.5% | Feb 3, 2021 | SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS. |
| CVE-2020-29582 | MEDIUM | 5.3 | 2.6% | Feb 3, 2021 | In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker wa... |
| CVE-2020-28001 | MEDIUM | 5.4 | 3.8% | Feb 3, 2021 | SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS. |
| CVE-2020-27994 | MEDIUM | 6.5 | 3.9% | Feb 3, 2021 | SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. |
| CVE-2020-25208 | MEDIUM | 5.3 | 1.4% | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permiss... |
| CVE-2020-29164 | MEDIUM | 6.1 | 5.4% | Feb 3, 2021 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS). |
| CVE-2020-24490 | MEDIUM | 6.5 | 2.2% | Feb 2, 2021 | Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adja... |
| CVE-2020-8734 | MEDIUM | 6.7 | 0.3% | Feb 2, 2021 | Improper input validation in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privilege... |
| CVE-2020-4081 | MEDIUM | 6.1 | 0.6% | Feb 2, 2021 | In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS). |
| CVE-2020-29662 | MEDIUM | 5.3 | 0.7% | Feb 2, 2021 | In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path. |
| CVE-2020-14221 | MEDIUM | 4.9 | 0.8% | Feb 2, 2021 | HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users. |
| CVE-2020-28498 | MEDIUM | 6.8 | 1.2% | Feb 2, 2021 | The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now