2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-4934MEDIUM4.3IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send...
CVE-2020-25035MEDIUM6.7UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a ...
CVE-2020-36231MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they sh...
CVE-2020-14192MEDIUM4.3Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Di...
CVE-2020-28493MEDIUM5.3This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation...
CVE-2020-25594MEDIUM5.3HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requ...
CVE-2020-13564MEDIUM6.1A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req...
CVE-2020-13563MEDIUM6.1A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req...
CVE-2020-13562MEDIUM6.1A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP req...
CVE-2020-17380MEDIUM6.3A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while...
CVE-2020-24670MEDIUM5.4The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerabilit...
CVE-2020-24669MEDIUM5.4The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerabi...
CVE-2020-24666MEDIUM5.4The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, w...
CVE-2020-24665MEDIUM6.5The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerabili...
CVE-2020-24664MEDIUM5.4The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerabilit...
CVE-2020-35652MEDIUM6.5An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 1...
CVE-2020-29605MEDIUM4.3An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed t...
CVE-2020-29604MEDIUM6.5An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (wit...
CVE-2020-29603MEDIUM4.3In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' n...
CVE-2020-29538MEDIUM4.9Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malic...
CVE-2020-29537MEDIUM5.4Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potential...
CVE-2020-29536MEDIUM4.3Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker w...
CVE-2020-29535MEDIUM5.4Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could p...
CVE-2020-28406MEDIUM6.5An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...
CVE-2020-28404MEDIUM6.5An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthori...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now