2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4934 | MEDIUM | 4.3 | 1.8% | Feb 2, 2021 | IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send... |
| CVE-2020-25035 | MEDIUM | 6.7 | 0.5% | Feb 2, 2021 | UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a ... |
| CVE-2020-36231 | MEDIUM | 4.3 | 1.2% | Feb 2, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they sh... |
| CVE-2020-14192 | MEDIUM | 4.3 | 0.9% | Feb 2, 2021 | Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Di... |
| CVE-2020-28493 | MEDIUM | 5.3 | 3.5% | Feb 1, 2021 | This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation... |
| CVE-2020-25594 | MEDIUM | 5.3 | 1.4% | Feb 1, 2021 | HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requ... |
| CVE-2020-13564 | MEDIUM | 6.1 | 75.9% | Feb 1, 2021 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req... |
| CVE-2020-13563 | MEDIUM | 6.1 | 75.9% | Feb 1, 2021 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req... |
| CVE-2020-13562 | MEDIUM | 6.1 | 77.7% | Feb 1, 2021 | A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req... |
| CVE-2020-17380 | MEDIUM | 6.3 | 0.4% | Jan 30, 2021 | A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while... |
| CVE-2020-24670 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerabilit... |
| CVE-2020-24669 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerabi... |
| CVE-2020-24666 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, w... |
| CVE-2020-24665 | MEDIUM | 6.5 | 1.1% | Jan 29, 2021 | The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerabili... |
| CVE-2020-24664 | MEDIUM | 5.4 | 0.6% | Jan 29, 2021 | The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerabilit... |
| CVE-2020-35652 | MEDIUM | 6.5 | 1.9% | Jan 29, 2021 | An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 1... |
| CVE-2020-29605 | MEDIUM | 4.3 | 0.9% | Jan 29, 2021 | An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed t... |
| CVE-2020-29604 | MEDIUM | 6.5 | 1.1% | Jan 29, 2021 | An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (wit... |
| CVE-2020-29603 | MEDIUM | 4.3 | 1.1% | Jan 29, 2021 | In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' n... |
| CVE-2020-29538 | MEDIUM | 4.9 | 1.0% | Jan 29, 2021 | Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malic... |
| CVE-2020-29537 | MEDIUM | 5.4 | 0.8% | Jan 29, 2021 | Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potential... |
| CVE-2020-29536 | MEDIUM | 4.3 | 0.5% | Jan 29, 2021 | Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker w... |
| CVE-2020-29535 | MEDIUM | 5.4 | 0.8% | Jan 29, 2021 | Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could p... |
| CVE-2020-28406 | MEDIUM | 6.5 | 1.3% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
| CVE-2020-28404 | MEDIUM | 6.5 | 1.3% | Jan 29, 2021 | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now